CVE-2026-42533
NGINX Map directive and Regex matching vulnerability
Affected
- ubuntu/nginx
1.18.0-6ubuntu14.21..* - ubuntu/nginx
1.24.0-2ubuntu7.18..* - ubuntu/nginx
1.28.3-2ubuntu1.11..*
Description
A flaw was found in NGINX. An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests when the `map` directive uses regular expression (regex) matching and references regex capture variables before referencing the map output variable. This can lead to a heap buffer overflow, which may allow for arbitrary code execution on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. Additionally, this flaw can cause a denial-of-service (DoS) due to the NGINX worker process restarting.
Affected operating systems
linux
ubuntu / nginxjammy
linux
ubuntu / nginxnoble
linux
ubuntu / nginxresolute
Metrics
Show all metrics
Weakness classes (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-10 15:28 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:f5:nginx_plus:r36:-:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 1.3.0 up to (including) 1.6.2 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.2.0 up to (including) 5.8.0 *cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:r36:p5:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* versions from (including) 2.0.0 up to (excluding) 2.6.7 *cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* versions from (including) 37.0.0.1 up to (excluding) 37.0.3.1 *cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* versions from (including) r33 up to (excluding) r36 *cpe:2.3:a:f5:nginx_plus:r36:p6:*:*:*:*:*:* *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 5.9.0 up to (excluding) 5.13.4 *cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* versions from (including) 4.11.0 up to (including) 4.16.0 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* versions from (including) 3.5.0 up to (including) 3.7.2 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:* versions from (including) 5.0.0 up to (excluding) 5.5.3 *cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:long-term_support:*:*:* versions from (including) 2026-lts-r1 up to (excluding) 2026-lts-r4 *cpe:2.3:a:f5:nginx_ingress_controller:4.0.0:*:*:*:continuous_releases:*:*:* *cpe:2.3:a:f5:nginx_ingress_controller:4.0.1:*:*:*:continuous_releases:*:*:*
- Reference Type: F5 Networks: https://my.f5.com/manage/s/article/K000162097 Types: Vendor Advisory
- CVE Modified2026-07-29 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-42533","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-42533","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
Linked advisories
- sans-atrisk-mail2026-08-06 00:00 UTC@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 30
- sans-atrisk-mail2026-07-30 00:00 UTC@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 29
- sans-newsbites-mail2026-07-24 00:00 UTCHealth-ISAC Warns of Increased Attacks from ShinyHunters Threat Actors