9.2
CRITICAL CVSS 4.0
CVE-2026-42533
NGINX Map directive and Regex matching vulnerability
Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

INFO

Published Date :

July 15, 2026, 3:16 p.m.

Last Modified :

July 29, 2026, 5:16 a.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2026-42533 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 F5 nginx_plus
2 F5 nginx_open_source
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 HIGH 9dacffd4-cb11-413f-8451-fbbfd4ddc0ab
CVSS 3.1 HIGH [email protected]
CVSS 4.0 CRITICAL 9dacffd4-cb11-413f-8451-fbbfd4ddc0ab
CVSS 4.0 CRITICAL [email protected]
Solution
Update NGINX to a patched version to fix heap buffer overflow and potential code execution.
  • Update NGINX Plus and Open Source to a patched version.
  • Apply vendor-provided patches and security updates.
  • Restart the NGINX worker process after updates.
Public PoC/Exploit Available at Github

CVE-2026-42533 has a 9 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-42533.

URL Resource
https://my.f5.com/manage/s/article/K000162097
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-42533 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-42533 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Shell Makefile Nix CSS HTML

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : July 21, 2026, 5:27 a.m. This repo has been linked 1 different CVEs too.

哪吒监控面板一键管理脚本 | 二进制原生安装 | Nginx 三S优化 | acme.sh 证书 | TG 到期推送与健康告警 | 自动更新与一键回退 | 自托管 TG 管理 Bot | Debian/Ubuntu

Shell

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : July 21, 2026, 4:21 a.m. This repo has been linked 1 different CVEs too.

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).

Updated: 2 weeks, 1 day ago
0 stars 0 fork 0 watcher
Born at : July 20, 2026, 7:22 a.m. This repo has been linked 2 different CVEs too.

Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.

detection-engineering microsoft-defender nginx splunk vulnerability-management cve-2026-42533

PowerShell Python

Updated: 2 weeks, 2 days ago
0 stars 1 fork 1 watcher
Born at : July 20, 2026, 1:20 a.m. This repo has been linked 1 different CVEs too.

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).

Python

Updated: 2 weeks ago
11 stars 3 fork 3 watcher
Born at : July 4, 2026, 11:05 a.m. This repo has been linked 1 different CVEs too.

Your 3D projects, organized your way.

Dockerfile Python Mako Shell HTML TypeScript CSS Makefile

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : June 27, 2026, 4:36 p.m. This repo has been linked 1 different CVEs too.

灵砚 Oraink 公开科技互联网日报/周报归档,汇聚公众号、推特、博客、Newsletter 等优质创作者与一线团队文章。

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : June 16, 2026, 2:03 p.m. This repo has been linked 2 different CVEs too.

WNMP One‑Click Stack | WebDAV · Nginx · PHP · MariaDB · Kernel Tuning

Shell

Updated: 2 weeks, 4 days ago
26 stars 4 fork 4 watcher
Born at : Dec. 7, 2025, 11:39 p.m. This repo has been linked 13 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 2 weeks, 2 days ago
7922 stars 1275 fork 1275 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 646 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-42533 vulnerability anywhere in the article.

  • The Cyber Express
Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster

Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Bui ... Read more

Published Date: Jul 22, 2026 (1 week, 6 days ago)
  • The Cyber Express
Estée Lauder Confirms Cyberattack Affecting Personal Information

The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human reso ... Read more

Published Date: Jul 21, 2026 (2 weeks ago)
  • The Cyber Express
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication. ... Read more

Published Date: Jul 20, 2026 (2 weeks, 1 day ago)
  • The Hacker News
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched ... Read more

Published Date: Jul 19, 2026 (2 weeks, 2 days ago)

The following table lists the changes that have been made to the CVE-2026-42533 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 29, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T00:00:00+00:00'} {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T00:00:00+00:00'}
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 16, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T15:37:45.453471Z'} {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T00:00:00+00:00'}
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 15, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T15:37:45.453471Z'}
  • New CVE Received by [email protected]

    Jul. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'F5', 'modules': ['map directive with regex matching'], 'product': 'NGINX Plus', 'versions': [{'status': 'affected', 'version': '37.0.0.1', 'lessThan': '37.0.3.1', 'versionType': 'custom'}, {'status': 'affected', 'version': 'R36', 'lessThan': 'R36 P7', 'versionType': 'custom'}, {'status': 'affected', 'version': 'R33', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'F5', 'modules': ['map directive with regex matching'], 'product': 'NGINX Open Source', 'versions': [{'status': 'affected', 'version': '1.31.2', 'lessThan': '1.31.3', 'versionType': 'custom'}, {'status': 'affected', 'version': '0.9.6', 'lessThan': '1.30.4', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}]
    Added Description A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    Added CVSS V4.0 AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-122
    Added Reference https://my.f5.com/manage/s/article/K000162097
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.