Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-42533: NGINX can crash or run malicious code via crafted web request

CVE-2026-42533 · published 2 months ago
Summary

Both NGINX Plus and the open‑source NGINX server may crash or, in rare cases, run attacker code when a specially crafted web request triggers a flaw in how certain configuration patterns are handled. This could lead to a temporary loss of service and, if the server’s memory protections are weak, allow the attacker to take control. Apply the latest patches from the vendor as soon as possible and restart the server after updating.

What to do
  • Update nginx-gateway to version 1.31.3.
  • Update nginx to version 1.31.3.
  • Update bellsoft nginx to version 1.30.4-r1.
  • Update debian rootio-nginx to version 1.26.3-3+deb13u7.aikido.1.
  • Update debian nginx to version 1.26.3-3+deb13u7.aikido.1.
  • Update alpine nginx to version 1.26.3-r00071.
  • Update alpine rootio-nginx to version 1.26.3-r00071.
  • Update alpine nginx to version 1.30.4-r0.
  • Update alpine nginx to version 1.26.3-r00072.
  • Update alpine rootio-nginx to version 1.26.3-r00072.
  • Update debian rootio-nginx to version 1.18.0-6.1+deb11u8.aikido.2.
  • Update debian nginx to version 1.18.0-6.1+deb11u8.aikido.2.
  • Update debian rootio-nginx to version 1.22.1-9+deb12u9.aikido.6.
  • Update debian nginx to version 1.22.1-9+deb12u9.aikido.6.
  • Update bellsoft nginx-base to version 1.30.4-r0.
  • Update bellsoft nginx-base to version 1.30.4-r1.
  • Update debian nginx to version 1.26.3-3+deb13u8.
  • Update debian nginx to version 1.30.4-3.
  • Update debian nginx to version 1.22.1-9+deb12u10.
  • Update f5 nginx plus to version 37.0.3.1 or later.
  • Update f5 nginx open source to version 1.31.3 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:26.04:LTS canonical nginx All versions
– f5 nginx plus < 37.0.3.1
– f5 nginx open source < 1.31.3
Ubuntu:Pro:14.04:LTS canonical nginx All versions
Ubuntu:Pro:16.04:LTS canonical nginx All versions
Ubuntu:Pro:18.04:LTS canonical nginx All versions
Ubuntu:Pro:20.04:LTS canonical nginx All versions
Ubuntu:22.04:LTS canonical nginx All versions
Ubuntu:24.04:LTS canonical nginx All versions
Bitnami – nginx-gateway >= 1.31.2, < 1.31.3
Fix: upgrade to 1.31.3
Bitnami – nginx >= 1.31.2, < 1.31.3
Fix: upgrade to 1.31.3
Alpaquita:stream bellsoft nginx >= 1.22.1-r0, < 1.30.4-r1
Fix: upgrade to 1.30.4-r1
Root:Debian:13 debian rootio-nginx < 1.26.3-3+deb13u7.aikido.1
Fix: upgrade to 1.26.3-3+deb13u7.aikido.1
Debian:11 debian nginx All versions
Debian:12 debian nginx < 1.22.1-9+deb12u10
Fix: upgrade to 1.22.1-9+deb12u10
Debian:13 debian nginx < 1.26.3-3+deb13u8
Fix: upgrade to 1.26.3-3+deb13u8
Debian:14 debian nginx < 1.30.4-3
Fix: upgrade to 1.30.4-3
Root:Debian:13 debian nginx < 1.26.3-3+deb13u7.aikido.1
Fix: upgrade to 1.26.3-3+deb13u7.aikido.1
Root:Alpine:3.20 alpine nginx < 1.26.3-r00071
< 1.26.3-r00072
Fix: upgrade to 1.26.3-r00071
Root:Alpine:3.20 alpine rootio-nginx < 1.26.3-r00071
< 1.26.3-r00072
Fix: upgrade to 1.26.3-r00071
Alpine:v3.24 alpine nginx < 1.30.4-r0
Fix: upgrade to 1.30.4-r0
Root:Debian:11 debian rootio-nginx < 1.18.0-6.1+deb11u8.aikido.2
Fix: upgrade to 1.18.0-6.1+deb11u8.aikido.2
Root:Debian:11 debian nginx < 1.18.0-6.1+deb11u8.aikido.2
Fix: upgrade to 1.18.0-6.1+deb11u8.aikido.2
Root:Debian:12 debian rootio-nginx < 1.22.1-9+deb12u9.aikido.6
Fix: upgrade to 1.22.1-9+deb12u9.aikido.6
Root:Debian:12 debian nginx < 1.22.1-9+deb12u9.aikido.6
Fix: upgrade to 1.22.1-9+deb12u9.aikido.6
Alpaquita:23 bellsoft nginx-base >= 1.30.3-r0, < 1.30.4-r0
Fix: upgrade to 1.30.4-r0
Alpaquita:25 bellsoft nginx >= 1.28.0-r3, < 1.30.4-r1
Fix: upgrade to 1.30.4-r1
Alpaquita:stream bellsoft nginx-base >= 1.30.3-r0, < 1.30.4-r1
Fix: upgrade to 1.30.4-r1
BellSoft Hardened Containers:23 bellsoft nginx-base >= 1.30.3-r0, < 1.30.4-r0
Fix: upgrade to 1.30.4-r0
Original advisory text
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map o...
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.

Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.




 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Severity
9.4 Critical
CVSS 3.1: 8.1 (NVD)
CVSS 4.0: 9.2 (NVD)
CVSS 3.1: 8.1 (OSV)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published15 Jul 2026
Updated27 Sep 2026
First seen15 Jul 2026
Track software like this
Free during beta