CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

CVE Advisories
Post Reply
Starburst-David
Posts: 286
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

Post by Starburst-David »

A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication. The issue affects nginx versions 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline), while patched releases include 1.30.4 and 1.31.3. Affected NGINX Plus versions include R33-R36 (fixed in R36 P7) and 37.0.0.1-37.0.2.1 (fixed in 37.0.3.1).

According to the disclosure, the vulnerability stems from a missing save-and-restore mechanism for PCRE capture state within nginx’s two-pass script evaluation engine. The flaw enables attackers to trigger a heap buffer overflow with attacker-controlled content and length, while also exposing heap pointers through an information leak that can defeat Address Space Layout Randomization (ASLR). Chaining both primitives enables reliable Pre-Auth nginx RCE.

More Information:
https://thecyberexpress.com/cve-2026-42 ... nginx-rce/

Published Date: Jul 20, 2026

Vulnerabilities has been mentioned in this article:
CVE-2026-53412 CVE-2026-42533 CVE-2026-48142 CVE-2026-42055 CVE-2026-9256 CVE-2026-42945
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”