A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
[POC] CVE-2026-42533 — CVE-2026-42533-POC
CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.
[POC] CVE-2026-42533 — CVE-2026-42533
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
[POC] GHSA-652q-gvq3-74qv — CVE-2026-42533-nginx
CVE-2026-42533 Nginx
[POC] CVE-2026-42533 — CVE-2026-42533-
Vulnerabilidad en NGINX
[POC] CVE-2026-42533 — CVE-2026-42533
Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow
[POC] CVE-2026-42533 — ghostlock-vagrant-box
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
[POC] CVE-2026-42533 — nginx-map-risk-audit
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
[POC] CVE-2026-42533 — CVE-2026-42533-Scanner
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free