CVE-2026-42533
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-122
Desbordamiento de búfer basado en memoria dinámica (Heap)
Fecha de publicación:
15/07/2026
Última modificación:
10/08/2026
Descripción
*** Pendiente de traducción *** A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map&#39;s regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.<br />
<br />
Impact:<br />
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.<br />
<br />
<br />
<br />
<br />
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impacto
Puntuación base 4.0
9.20
Gravedad 4.0
CRÍTICA
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* | 1.3.0 (incluyendo) | 1.6.2 (incluyendo) |
| cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* | 2.0.0 (incluyendo) | 2.6.7 (excluyendo) |
| cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* | 3.5.0 (incluyendo) | 3.7.2 (incluyendo) |
| cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* | 5.0.0 (incluyendo) | 5.5.3 (excluyendo) |
| cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:long-term_support:*:*:* | 2026-lts-r1 (incluyendo) | 2026-lts-r4 (excluyendo) |
| cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:continuous_releases:*:*:* | ||
| cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:continuous_releases:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* | 37.0.0.1 (incluyendo) | 37.0.3.1 (excluyendo) |
| cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* | r33 (incluyendo) | r36 (excluyendo) |
| cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



