CVE detail
CVE-2026-42533
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 5.0
Why it matters now
Mention timeline
- Total mentions
- 11
- within the 30d window
- Peak daily
- 3
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability HuntingSecurity Affairs
d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities
newssecurityaffairs.comJul 23, 2026, 11:44 AM d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities
newssecurityaffairs.comJul 22, 2026, 8:51 AMInformation published.
vendormsrc.microsoft.comJul 22, 2026, 8:41 AM- Zimbra 10.1.20 patches multiple security issues, including a critical command injection bugSecurity Affairs
d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities
newssecurityaffairs.comJul 21, 2026, 6:25 PM - ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News
on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo
newsthehackernews.comJul 20, 2026, 1:32 PM F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow
newssecurityaffairs.comJul 20, 2026, 9:50 AMContact me MUST READ Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! | CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers | AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign | Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appl
newssecurityaffairs.comJul 20, 2026, 8:21 AMets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of
newsthehackernews.comJul 19, 2026, 8:42 PM- OpenSSL Fixes HollowByte Memory Exhaustion BugSecurity Affairs
Contact me MUST READ Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! | CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers | AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign | Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appl
newssecurityaffairs.comJul 18, 2026, 6:24 PM nounced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP. The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker process. “A vulnerability exists i
newswww.securityweek.comJul 16, 2026, 9:20 AMNo excerpt available.
Vendor Advisorymy.f5.comJul 15, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.99 · max 0 stars
- gagaltotal/CVE-2026-42533-nginxHigh confidencegithubRepository topic discovery0 starsDiscovered Jul 23, 2026, 10:51 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66040CVSS 8.7 · High
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap m…
- CVE-2026-66039CVSS 8.7 · High
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplyin…
- CVE-2026-66036CVSS 7.7 · High
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying…
- CVE-2026-66035CVSS 7.7 · High
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in an…
- CVE-2026-56392CVSS 1.8 · Low
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplica…
- CVE-2026-56165CVSS 9.8 · Critical
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.