NGINX heap buffer overflow (CVE‑2026‑42533) enables remote code execution
A high‑severity heap buffer overflow (CVE‑2026‑42533) has been identified in NGINX Plus and NGINX Open Source. The flaw occurs in configurations that use regex‑based map directives or non‑cacheable variables within string expressions, and it is especially exploitable when the Stream module’s ssl_preread feature processes crafted TLS traffic before authentication.
Unauthenticated attackers can send specially crafted HTTP or TLS requests that trigger the overflow, causing the NGINX worker process to crash and, under certain conditions such as disabled ASLR, allowing remote code execution on the host. A proof‑of‑concept exploit has been released, raising the risk of weaponisation. Security advisories from F5 Networks (July 15, 2026) and the Uganda National Computer Emergency Response Team urge administrators to apply patches immediately, audit configurations for risky regex maps, and consider disabling ssl_preread where unnecessary.
Entities: Depth First Labs · F5 Networks · NGINX · Uganda National Computer Emergency Response Team · Zhenpeng (Leo) Lin