Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
Overview
F5 has released important updates to address a critical vulnerability in NGINX, identified as CVE-2026-42533. This flaw allows attackers to send specially crafted HTTP requests that can cause a heap buffer overflow in the NGINX worker process. As a result, this vulnerability could lead to the crashing or restarting of the worker, effectively denying service to legitimate users. The issue affects versions of NGINX prior to 1.30.4 and 1.31.3, as well as NGINX Plus versions before 37.0.3.1. Users running these versions should upgrade immediately to protect their systems from potential exploitation.
Key Takeaways
- Affected Systems: NGINX versions prior to 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus versions before 37.0.3.1.
- Action Required: Upgrade to NGINX version 1.
- Timeline: Disclosed on July 15, 2023
Original Article Summary
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of
Impact
NGINX versions prior to 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus versions before 37.0.3.1.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on July 15, 2023
Remediation
Upgrade to NGINX version 1.30.4 or 1.31.3, or NGINX Plus version 37.0.3.1 or later.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Critical, and 2 more.