Visualização de leitura

CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers

F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests.

F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.

“heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).” reads the advisory.

CVE-2026-42533 affects NGINX Plus and Open Source when specific regex-based map configurations are used. An unauthenticated attacker can send crafted HTTP requests to trigger a heap buffer overflow, causing crashes or denial of service. In certain conditions, especially if ASLR is disabled or bypassed, the flaw may also allow remote code execution. The issue affects only the data plane, not the control plane.

The vulnerability affects NGINX versions from 0.9.6 through 1.31.2. F5 fixed the issue in NGINX 1.30.4, 1.31.3 and NGINX Plus 37.0.3.1. The flaw impacts only the data plane and does not expose the NGINX control plane.

As a temporary workaround, affected regex-based map configurations can be modified to use named captures instead of numbered captures, but this does not provide complete protection.

The researchers Mufeed VH of Winfunc Research and Maxim Dounin discovered the vulnerability.

Security researcher Stan Shaw (cyberstan) reported that CVE-2026-42533 may have a higher impact than initially described by F5. While F5 highlights denial-of-service risks, Shaw believes the flaw could also help attackers bypass ASLR protections and achieve remote code execution under certain conditions. He has not released exploit details or a proof-of-concept yet.

Shaw released a static scanner that identifies vulnerable NGINX configurations without exploiting the flaw. The tool checks include files, analyzes directive relationships, and detects exploitable patterns. Shaw is delaying publication of the proof-of-concept and technical exploitation details to give organizations time to patch, noting that similar NGINX flaws were exploited soon after PoCs became public.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, F5)

CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

CVE-2026-42533

A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication. The issue affects nginx versions 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline), while patched releases include 1.30.4 and 1.31.3. Affected NGINX Plus versions include R33-R36 (fixed in R36 P7) and 37.0.0.1-37.0.2.1 (fixed in 37.0.3.1).  According to the disclosure, the vulnerability stems from a missing save-and-restore mechanism for PCRE capture state within nginx's two-pass script evaluation engine. The flaw enables attackers to trigger a heap buffer overflow with attacker-controlled content and length, while also exposing heap pointers through an information leak that can defeat Address Space Layout Randomization (ASLR). Chaining both primitives enables reliable Pre-Auth nginx RCE. 

CVE-2026-42533 Impacts Multiple Configurations 

The advisory warns that deployments using map directives with regex patterns alongside regex capture sources, including location, server_name, rewrite, or if blocks, may be vulnerable. The issue depends on evaluation order, where regex capture references, such as $1 or named groups, are processed before a regex map variable.  Affected directives include proxy_set_header, proxy_method, proxy_pass, fastcgi_param, uwsgi_param, scgi_param, grpc_set_header, return, add_header, rewrite, set, root, alias, and access_log, among others. Both HTTP and stream modules are affected, and the vulnerable capture and map variables do not need to exist within the same directive. 

Technical Root Cause

The researcher explained that nginx evaluates expressions in two stages: a length calculation (LEN) pass followed by a value (VALUE) pass. During execution, regex map evaluation overwrites shared capture data stored in the request object. As a result, the LEN pass and VALUE pass can calculate different capture sizes, causing either a heap overflow or an information leak depending on the relative capture lengths.  The disclosure states that attackers can control both the overflow size and leaked data using ordinary HTTP requests, including request URIs, headers, and bodies. No credentials, client certificates, or unusual configuration beyond the vulnerable pattern are required.  Testing reportedly achieved 10 out of 10 successful exploitations on Ubuntu 24.04 using glibc 2.39 with ASLR enabled.

Mitigation and Disclosure

The researcher said recent fixes for CVE-2026-42945, CVE-2026-9256, CVE-2026-42055, and CVE-2026-48142 do not address CVE-2026-42533. Administrators are advised to upgrade immediately to nginx 1.30.4, 1.31.3, or the corresponding patched NGINX Plus releases.  Until systems are updated, defenders should audit configurations that combine regex captures with regex map variables in the same evaluation path. The researcher also released a static configuration scanner that identifies vulnerable configurations without exploiting them.  The initial report was submitted to F5 SIRT on May 17, 2026, with follow-up analyses covering additional variants, including cross-directive triggering and named capture clobbering. While a proof-of-concept exploit exists, the researcher said it will be withheld until users have sufficient time to apply patches, citing concerns over rapid exploitation following previous nginx vulnerability disclosures. 
❌