Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2026-42533 — nginx-gateway-fabric

CVE-2026-42533 is a CWE-122 vulnerability. 2 public exploit references exist, so weaponization risk is real. A fix is available — see the affected versions and patch details below.

Also known asBIT-nginx-2026-42533BIT-nginx-gateway-2026-42533
Published
Jul 15, 2026
Updated
Sep 16, 2026
Affected
4 products
Patched
See advisory
Exploits
2 known
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-42533.

EPSS Exploitation Probability

via FIRST.org ↗
0.9%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs58th percentile — riskier than 58% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.

Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.

 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

4 products · 19 configurations
Application
nginx gateway fabricf5
≥ 2.0.0 && ≤ 1.6.2
range
Application
nginx ingress controllerf5
≥ 2026-lts-r1 && ≤ 3.7.2
2 versions
4.0.04.0.1
Application
nginx plusf5
≥ r33 && < r36
1 version
r36
Application
waff5
≥ 5.9.0 && ≤ 5.8.0
range
Exploits & PoCs
2

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Fix

    Upgrade the affected component to the fixed release for CVE-2026-42533, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.

  3. Workarounds

    Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant

This vulnerability in NGINX allows a remote, unauthenticated attacker to trigger a heap buffer overflow, leading to a denial of service (Dos). This occurs when the `map` directive uses regex matching and references regex capture variables before the map output variable. While arbitrary code execution is a theoretical…

Workaround published by Red Hat
To mitigate this vulnerability, do not use unnamed captures. Use named captures instead and only use them in the same block with the regex match. Red Hat recommends updating nginx to the latest version when a fix is available.
Source: Red Hat security advisory for CVE-2026-42533 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat Enterprise Linux 10nginx-2:1.26.3-6.el10_2.7RHSA-2026:67314
Red Hat Enterprise Linux 8nginx:1.24-8100020260908154808.489197e6RHSA-2026:67315
Red Hat Enterprise Linux 9nginx-2:1.20.1-28.el9_8.6RHSA-2026:66542
Red Hat Enterprise Linux 9nginx:1.26-9080020260908105507.9RHSA-2026:67283
Red Hat Enterprise Linux 9nginx:1.24-9080020260908110425.9RHSA-2026:67308
Red Hat Hardened Imagesnginx-main-1.30.4-2.hum1RHSA-2026:46012

Frequently Asked Questions

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can exe
O3 Security · Impact-Aware SCA

Is CVE-2026-42533 in your dependencies?

Find it across , including transitive dependencies.

CVE-2026-42533: nginx-gateway | O3 Security