CVE-2026-42533 — nginx-gateway-fabric
CVE-2026-42533 is a CWE-122 vulnerability. 2 public exploit references exist, so weaponization risk is real. A fix is available — see the affected versions and patch details below.
Exploitation Status
No confirmed exploitation observed yet
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-42533.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products
nginx gateway fabricf5nginx ingress controllerf5nginx plusf5waff5Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Fix
Upgrade the affected component to the fixed release for CVE-2026-42533, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.
Workarounds
Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This vulnerability in NGINX allows a remote, unauthenticated attacker to trigger a heap buffer overflow, leading to a denial of service (Dos). This occurs when the `map` directive uses regex matching and references regex capture variables before the map output variable. While arbitrary code execution is a theoretical…
To mitigate this vulnerability, do not use unnamed captures. Use named captures instead and only use them in the same block with the regex match. Red Hat recommends updating nginx to the latest version when a fix is available.Source: Red Hat security advisory for CVE-2026-42533 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 10 | nginx-2:1.26.3-6.el10_2.7 | RHSA-2026:67314 |
| Red Hat Enterprise Linux 8 | nginx:1.24-8100020260908154808.489197e6 | RHSA-2026:67315 |
| Red Hat Enterprise Linux 9 | nginx-2:1.20.1-28.el9_8.6 | RHSA-2026:66542 |
| Red Hat Enterprise Linux 9 | nginx:1.26-9080020260908105507.9 | RHSA-2026:67283 |
| Red Hat Enterprise Linux 9 | nginx:1.24-9080020260908110425.9 | RHSA-2026:67308 |
| Red Hat Hardened Images | nginx-main-1.30.4-2.hum1 | RHSA-2026:46012 |
Frequently Asked Questions
Is CVE-2026-42533 in your dependencies?
Find it across , including transitive dependencies.