Feed/CVE-2026-42533
CVE-2026-42533HIGHCVSS 8.1

CVE-2026-42533

Published Jul 15, 2026·Updated Aug 10, 2026

NVD Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Public Exploits & PoCs8 found

[POC] CVE-2026-42533 — CVE-2026-42533-POC

CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.

[POC] CVE-2026-42533 — CVE-2026-42533

nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.

[POC] GHSA-652q-gvq3-74qv — CVE-2026-42533-nginx

CVE-2026-42533 Nginx

[POC] CVE-2026-42533 — CVE-2026-42533-

Vulnerabilidad en NGINX

[POC] CVE-2026-42533 — CVE-2026-42533

Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow

[POC] CVE-2026-42533 — ghostlock-vagrant-box

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).

[POC] CVE-2026-42533 — nginx-map-risk-audit

Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.

[POC] CVE-2026-42533 — CVE-2026-42533-Scanner

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free