Security · 20h ago
Critical NGINX Bug Allows Remote Heap Overflow, DoS
F5 patched CVE-2026-42533, a critical heap buffer overflow in nginx that lets unauthenticated attackers crash worker processes via crafted HTTP requests. The flaw affects nginx stable 1.30.4 and mainline 1.31.3, plus NGINX Plus 37.0.3.1, released July 15. Users on earlier builds should upgrade immediately to prevent denial-of-service or potential remote code execution.
Meridian48 take
While F5 downplays RCE risk, the heap overflow vector is serious enough that admins should treat this as a priority patch, especially for exposed instances.
Read the full reporting
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution →
The Hacker News
nginx-vulnerabilityheap-buffer-overflow