Critical NGINX Flaw Enables Worker Crashes and Potential Remote Code Execution

F5 has patched CVE-2026-42533, a critical NGINX heap buffer overflow that unauthenticated attackers can trigger with crafted HTTP requests under specific regex-map configurations. The flaw affects NGINX 0.9.6 through 1.31.2 and can crash worker processes, while remote code execution may be possible if ASLR is disabled or bypassed. Users should upgrade to NGINX 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1, as the suggested named-capture mitigation may not block every attack path. No public exploit or confirmed active exploitation had been reported as of July 20, but proof-of-concept code is expected after the patch window.

Reference: thehackernews.com