F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Triggering it can crash or restart the worker, causing a denial of service; where ASLR is disabled or can be bypassed, F5 says it may also allow remote code execution.
More Information:
https://thehackernews.com/2026/07/criti ... crash.html
Published Date: Jul 19, 2026
Vulnerabilities has been mentioned in this article:
CVE-2026-42533 CVE-2026-9256 CVE-2026-42945
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
-
Starburst-David
- Posts: 286
- Joined: Wed Feb 11, 2026 8:31 pm