
A critical security flaw (CVE-2026-42533) has been discovered in the Nginx web server. The vulnerability lies in the map directive module, which handles variable mapping during regular expression processing. Remote attackers can send crafted HTTP requests without authentication to trigger a heap buffer overflow.
What Attackers Can Do
A successful exploit initially causes the server to crash, resulting in a denial of service. If ASLR is disabled or can be bypassed, attackers can also inject malicious code and fully compromise the system. The bar for exploitation is relatively low. F5 has not reported active attacks so far, but that can change quickly.
Affected Versions and Fixes
Nginx versions 0.9.6 through 1.31.2 are vulnerable. The issue is fixed in versions 1.31.3 and 1.30.4. For F5 products that ship Nginx, some fixes are already available: Nginx Plus 37.0.3.1 and R36 P7, Nginx Open Source 1.31.3 and 1.30.4, Nginx Gateway Fabric 2.6.7, and Nginx Ingress Controller 2026-lts-r45.5.3. Nginx Instance Manager and Nginx App Protect WAF updates are still pending. Admins should apply available patches promptly.