CVE-2026-42533
Description
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
14- osv-coords12 versionspkg:apk/chainguard/commercial-nginx-pluspkg:apk/chainguard/ingress-nginx-controller-1.15pkg:apk/chainguard/ingress-nginx-controller-fips-1.15pkg:apk/chainguard/nginx-mainlinepkg:apk/chainguard/nginx-stablepkg:apk/wolfi/ingress-nginx-controller-1.15pkg:apk/wolfi/nginx-mainlinepkg:apk/wolfi/nginx-stablepkg:bitnami/nginxpkg:bitnami/nginx-gatewaypkg:rpm/opensuse/nginx&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/nginx&distro=openSUSE%20Tumbleweed
< 37.0.3.1-r0+ 11 more
- (no CPE)range: < 37.0.3.1-r0
- (no CPE)range: < 1.15.10-r0
- (no CPE)range: < 1.15.10-r0
- (no CPE)range: < 1.31.3-r0
- (no CPE)range: < 1.30.4-r0
- (no CPE)range: < 1.15.10-r0
- (no CPE)range: < 1.31.3-r0
- (no CPE)range: < 1.30.4-r0
- (no CPE)range: >= 0.9.6, < 1.30.4
- (no CPE)range: >= 0.9.6, < 1.30.4
- (no CPE)range: < 1.27.2-160000.7.1
- (no CPE)range: < 1.31.3-1.1
Patches
Vulnerability mechanics
References
1- my.f5.com/manage/s/article/K000162097nvdVendor Advisory
News mentions
7- Nginx Buffer Overflow Vulnerability Allows Attackers to Execute Arbitrary Code – PoC ReleasedCyber Security News · Jul 28, 2026
- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 StoriesCyber Security News · Jul 26, 2026
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News · Jul 20, 2026
- 15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code ExecutionCyber Security News · Jul 20, 2026
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionThe Hacker News · Jul 19, 2026
- F5 Patches Multiple NGINX, BIG-IP VulnerabilitiesSecurityWeek · Jul 16, 2026
- F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution AttacksCyber Security News · Jul 16, 2026