Skip to content

Critical NGINX Vulnerability Enables DoS and Potentially Remote Code Execution

Bottom line: CVE-2026-42533 in NGINX 1.30.3, 1.31.2 and older NGINX Plus versions enables denial-of-service and potentially code execution — immediate update to 1.30.4, 1.31.3, or Plus 37.0.3.1 required.

F5 has patched a critical flaw in NGINX that allows unauthenticated attackers to trigger a heap buffer overflow in the worker process via specially crafted HTTP requests. The update has been available since July 15, 2026.

F5 has released patches for CVE-2026-42533, a critical vulnerability in NGINX that allows unauthenticated remote attackers to trigger a heap buffer overflow in the worker process. The vulnerability is triggered by specially crafted HTTP requests and affects NGINX 1.30.3, 1.31.2, as well as all earlier versions and older builds of NGINX Plus.

A successful attack leads to a crash or restart of the worker process, resulting in a denial-of-service situation. The buffer overflow nature of the vulnerability also carries the risk of remote code execution if an attacker exploits the flaw accordingly. Since no authentication is required, any network client can send the requests.

As a CISO you should immediately verify which NGINX versions are running in your infrastructure. Affected installations must be updated to NGINX 1.30.4 (stable branch), 1.31.3 (mainline), or NGINX Plus 37.0.3.1. The patches have been available since July 15, 2026. This applies especially to publicly reachable NGINX instances in edge positions or as load balancers.


Source: thehackernews.com · Published July 19, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: