CVE-2026-42533

Severity CVSS v4.0:
CRITICAL
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
15/07/2026
Last modified:
10/08/2026

Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map&amp;#39;s regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.<br /> <br /> Impact:<br /> This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.<br /> <br /> <br /> <br /> <br />  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* 1.3.0 (including) 1.6.2 (including)
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* 2.0.0 (including) 2.6.7 (excluding)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* 3.5.0 (including) 3.7.2 (including)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* 5.0.0 (including) 5.5.3 (excluding)
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:long-term_support:*:*:* 2026-lts-r1 (including) 2026-lts-r4 (excluding)
cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:continuous_releases:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* 37.0.0.1 (including) 37.0.3.1 (excluding)
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* r33 (including) r36 (excluding)
cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:*


References to Advisories, Solutions, and Tools