CVE-2026-42533
NGINX Map directive and Regex matching vulnerability
Description
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
INFO
Published Date :
July 15, 2026, 3:16 p.m.
Last Modified :
July 29, 2026, 5:16 a.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | 9dacffd4-cb11-413f-8451-fbbfd4ddc0ab | ||||
| CVSS 3.1 | HIGH | [email protected] | ||||
| CVSS 4.0 | CRITICAL | 9dacffd4-cb11-413f-8451-fbbfd4ddc0ab | ||||
| CVSS 4.0 | CRITICAL | [email protected] |
Solution
- Update NGINX Plus and Open Source to a patched version.
- Apply vendor-provided patches and security updates.
- Restart the NGINX worker process after updates.
Public PoC/Exploit Available at Github
CVE-2026-42533 has a 9 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-42533.
| URL | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K000162097 |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-42533 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-42533
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
Shell Makefile Nix CSS HTML
哪吒监控面板一键管理脚本 | 二进制原生安装 | Nginx 三S优化 | acme.sh 证书 | TG 到期推送与健康告警 | 自动更新与一键回退 | 自托管 TG 管理 Bot | Debian/Ubuntu
Shell
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
detection-engineering microsoft-defender nginx splunk vulnerability-management cve-2026-42533
PowerShell Python
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
Python
Your 3D projects, organized your way.
Dockerfile Python Mako Shell HTML TypeScript CSS Makefile
灵砚 Oraink 公开科技互联网日报/周报归档,汇聚公众号、推特、博客、Newsletter 等优质创作者与一线团队文章。
WNMP One‑Click Stack | WebDAV · Nginx · PHP · MariaDB · Kernel Tuning
Shell
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
security cve exploit poc vulnerability
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-42533 vulnerability anywhere in the article.
-
The Cyber Express
Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster
Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Bui ... Read more
-
The Cyber Express
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human reso ... Read more
-
The Cyber Express
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication. ... Read more
-
The Hacker News
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched ... Read more
The following table lists the changes that have been made to the
CVE-2026-42533 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jul. 29, 2026
Action Type Old Value New Value Changed SSVC {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T00:00:00+00:00'} {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T00:00:00+00:00'} -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jul. 16, 2026
Action Type Old Value New Value Changed SSVC {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T15:37:45.453471Z'} {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T00:00:00+00:00'} -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jul. 15, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-42533', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-15T15:37:45.453471Z'} -
New CVE Received by [email protected]
Jul. 15, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'F5', 'modules': ['map directive with regex matching'], 'product': 'NGINX Plus', 'versions': [{'status': 'affected', 'version': '37.0.0.1', 'lessThan': '37.0.3.1', 'versionType': 'custom'}, {'status': 'affected', 'version': 'R36', 'lessThan': 'R36 P7', 'versionType': 'custom'}, {'status': 'affected', 'version': 'R33', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'F5', 'modules': ['map directive with regex matching'], 'product': 'NGINX Open Source', 'versions': [{'status': 'affected', 'version': '1.31.2', 'lessThan': '1.31.3', 'versionType': 'custom'}, {'status': 'affected', 'version': '0.9.6', 'lessThan': '1.30.4', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}] Added Description A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Added CVSS V4.0 AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-122 Added Reference https://my.f5.com/manage/s/article/K000162097