Skip to main content

CVE detail

CVE-2026-42533

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS 9.2 · CriticalBuzz score 47.81 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 47.8

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.9 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 5.0
Mention score
24.9
11 evidence mentions in the snapshot
Diversity score
18.0
5 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
5.0
1 repos · best confidence 0.99
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
11
within the 30d window
Peak daily
3
highest bucket

Evidence

Source links by recency

Newest mentions first
11 source links · newest first
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 23, 2026, 11:44 AM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 22, 2026, 8:51 AM
  • Information published.

    vendormsrc.microsoft.comJul 22, 2026, 8:41 AM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 21, 2026, 6:25 PM
  • on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo

    newsthehackernews.comJul 20, 2026, 1:32 PM
  • F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow

    newssecurityaffairs.comJul 20, 2026, 9:50 AM
  • Contact me MUST READ Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! | CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers | AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign | Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appl

    newssecurityaffairs.comJul 20, 2026, 8:21 AM
  • ets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of

    newsthehackernews.comJul 19, 2026, 8:42 PM
  • OpenSSL Fixes HollowByte Memory Exhaustion BugSecurity Affairs

    Contact me MUST READ Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! | CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers | AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign | Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appl

    newssecurityaffairs.comJul 18, 2026, 6:24 PM
  • nounced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP. The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker process. “A vulnerability exists i

    newswww.securityweek.comJul 16, 2026, 9:20 AM
  • No excerpt available.

    Vendor Advisorymy.f5.comJul 15, 2026, 3:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 0 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-66040

    FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap m…

    CVSS 8.7 · High
    3 mentions
  • CVE-2026-66039

    FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplyin…

    CVSS 8.7 · High
    3 mentions
  • CVE-2026-66036

    FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying…

    CVSS 7.7 · High
    3 mentions
  • CVE-2026-66035

    libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in an…

    CVSS 7.7 · High
    3 mentions
  • CVE-2026-56392

    GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplica…

    CVSS 1.8 · Low
    3 mentions
  • CVE-2026-56165

    Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

    CVSS 9.8 · Critical
    1 mention