A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication. The issue affects nginx versions 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline), while patched releases include 1.30.4 and 1.31.3. Affected NGINX Plus versions include R33-R36 (fixed in R36 P7) and 37.0.0.1-37.0.2.1 (fixed in 37.0.3.1).
According to the disclosure, the vulnerability stems from a missing save-and-restore mechanism for PCRE capture state within nginx’s two-pass script evaluation engine. The flaw enables attackers to trigger a heap buffer overflow with attacker-controlled content and length, while also exposing heap pointers through an information leak that can defeat Address Space Layout Randomization (ASLR). Chaining both primitives enables reliable Pre-Auth nginx RCE.
More Information:
https://thecyberexpress.com/cve-2026-42 ... nginx-rce/
Published Date: Jul 20, 2026
Vulnerabilities has been mentioned in this article:
CVE-2026-53412 CVE-2026-42533 CVE-2026-48142 CVE-2026-42055 CVE-2026-9256 CVE-2026-42945
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
-
Starburst-David
- Posts: 286
- Joined: Wed Feb 11, 2026 8:31 pm