Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-42533: NGINX can crash or run malicious code via crafted web request
CVE-2026-42533 · published 2 months ago
Summary
Both NGINX Plus and the open‑source NGINX server may crash or, in rare cases, run attacker code when a specially crafted web request triggers a flaw in how certain configuration patterns are handled. This could lead to a temporary loss of service and, if the server’s memory protections are weak, allow the attacker to take control. Apply the latest patches from the vendor as soon as possible and restart the server after updating.
What to do
- Update nginx-gateway to version 1.31.3.
- Update nginx to version 1.31.3.
- Update bellsoft nginx to version 1.30.4-r1.
- Update debian rootio-nginx to version 1.26.3-3+deb13u7.aikido.1.
- Update debian nginx to version 1.26.3-3+deb13u7.aikido.1.
- Update alpine nginx to version 1.26.3-r00071.
- Update alpine rootio-nginx to version 1.26.3-r00071.
- Update alpine nginx to version 1.30.4-r0.
- Update alpine nginx to version 1.26.3-r00072.
- Update alpine rootio-nginx to version 1.26.3-r00072.
- Update debian rootio-nginx to version 1.18.0-6.1+deb11u8.aikido.2.
- Update debian nginx to version 1.18.0-6.1+deb11u8.aikido.2.
- Update debian rootio-nginx to version 1.22.1-9+deb12u9.aikido.6.
- Update debian nginx to version 1.22.1-9+deb12u9.aikido.6.
- Update bellsoft nginx-base to version 1.30.4-r0.
- Update bellsoft nginx-base to version 1.30.4-r1.
- Update debian nginx to version 1.26.3-3+deb13u8.
- Update debian nginx to version 1.30.4-3.
- Update debian nginx to version 1.22.1-9+deb12u10.
- Update f5 nginx plus to version 37.0.3.1 or later.
- Update f5 nginx open source to version 1.31.3 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:26.04:LTS | canonical | nginx | All versions |
| – | f5 | nginx plus | < 37.0.3.1 |
| – | f5 | nginx open source | < 1.31.3 |
| Ubuntu:Pro:14.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | nginx | All versions |
| Ubuntu:22.04:LTS | canonical | nginx | All versions |
| Ubuntu:24.04:LTS | canonical | nginx | All versions |
| Bitnami | – | nginx-gateway |
>= 1.31.2, < 1.31.3 Fix: upgrade to 1.31.3
|
| Bitnami | – | nginx |
>= 1.31.2, < 1.31.3 Fix: upgrade to 1.31.3
|
| Alpaquita:stream | bellsoft | nginx |
>= 1.22.1-r0, < 1.30.4-r1 Fix: upgrade to 1.30.4-r1
|
| Root:Debian:13 | debian | rootio-nginx |
< 1.26.3-3+deb13u7.aikido.1 Fix: upgrade to 1.26.3-3+deb13u7.aikido.1
|
| Debian:11 | debian | nginx | All versions |
| Debian:12 | debian | nginx |
< 1.22.1-9+deb12u10 Fix: upgrade to 1.22.1-9+deb12u10
|
| Debian:13 | debian | nginx |
< 1.26.3-3+deb13u8 Fix: upgrade to 1.26.3-3+deb13u8
|
| Debian:14 | debian | nginx |
< 1.30.4-3 Fix: upgrade to 1.30.4-3
|
| Root:Debian:13 | debian | nginx |
< 1.26.3-3+deb13u7.aikido.1 Fix: upgrade to 1.26.3-3+deb13u7.aikido.1
|
| Root:Alpine:3.20 | alpine | nginx |
< 1.26.3-r00071 < 1.26.3-r00072 Fix: upgrade to 1.26.3-r00071
|
| Root:Alpine:3.20 | alpine | rootio-nginx |
< 1.26.3-r00071 < 1.26.3-r00072 Fix: upgrade to 1.26.3-r00071
|
| Alpine:v3.24 | alpine | nginx |
< 1.30.4-r0 Fix: upgrade to 1.30.4-r0
|
| Root:Debian:11 | debian | rootio-nginx |
< 1.18.0-6.1+deb11u8.aikido.2 Fix: upgrade to 1.18.0-6.1+deb11u8.aikido.2
|
| Root:Debian:11 | debian | nginx |
< 1.18.0-6.1+deb11u8.aikido.2 Fix: upgrade to 1.18.0-6.1+deb11u8.aikido.2
|
| Root:Debian:12 | debian | rootio-nginx |
< 1.22.1-9+deb12u9.aikido.6 Fix: upgrade to 1.22.1-9+deb12u9.aikido.6
|
| Root:Debian:12 | debian | nginx |
< 1.22.1-9+deb12u9.aikido.6 Fix: upgrade to 1.22.1-9+deb12u9.aikido.6
|
| Alpaquita:23 | bellsoft | nginx-base |
>= 1.30.3-r0, < 1.30.4-r0 Fix: upgrade to 1.30.4-r0
|
| Alpaquita:25 | bellsoft | nginx |
>= 1.28.0-r3, < 1.30.4-r1 Fix: upgrade to 1.30.4-r1
|
| Alpaquita:stream | bellsoft | nginx-base |
>= 1.30.3-r0, < 1.30.4-r1 Fix: upgrade to 1.30.4-r1
|
| BellSoft Hardened Containers:23 | bellsoft | nginx-base |
>= 1.30.3-r0, < 1.30.4-r0 Fix: upgrade to 1.30.4-r0
|
Original advisory text
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map o...
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
- https://my.f5.com/manage/s/article/K000162097 Vendor Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-42533 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42533 URL
- https://docs.bell-sw.com/security/cves/CVE-2026-42533 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-42533 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-42533 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-42533 Vendor Advisory
- https://cyberstan.co.uk/nginx-rce/ Third Party Advisory
- https://github.com/imbas007/cve-2026-42533 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8563-1 Vendor Advisory
- https://ubuntu.com/security/notices/USN-8563-2 Vendor Advisory
- https://ubuntu.com/security/notices/USN-8563-3 Vendor Advisory
- https://ubuntu.com/security/notices/USN-8563-4 Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 8.1 (NVD)
CVSS 4.0: 9.2 (NVD)
CVSS 3.1: 8.1 (OSV)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published15 Jul 2026
Updated27 Sep 2026
First seen15 Jul 2026
Sources
UBUNTU-CVE-2026-42533 · OSV
ALPINE-CVE-2026-42533 · OSV
CVE-2026-42533 · NVD
CVE-2026-42533 · MITRE
BIT-nginx-2026-42533 · OSV
BELL-CVE-2026-42533 · OSV
DEBIAN-CVE-2026-42533 · OSV
CVE-2026-42533 · OSV
Track software like this
Free during beta