INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Critical NGINX Bug Could Turn HTTP Requests into Server Takeovers
| 2026-07-20 09:50 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The newly discovered critical NGINX vulnerability, CVE-2026-42533, has the potential to turn HTTP requests into server takeovers. This flaw affects versions of NGINX from 0.9.6 through 1.31.2 and can be exploited by unauthenticated attackers using specially crafted HTTP requests. The vulnerability may also allow remote code execution under certain conditions, making it a significant threat to organizations relying on the affected software. F5 has released patches for the issue in NGINX versions from 1.30.4 onwards, but earlier builds are still at risk of being compromised.
Technical Mitigations AI-generated
* Use named captures instead of numbered captures when crafting HTTP requests to avoid buffer overflows and remote code execution vulnerabilities.
* Implement ASLR (Address Space Layout Randomization) protection on NGINX servers, as disabling or bypassing it may allow attackers to exploit the heap buffer overflow vulnerability.
* Regularly review and update regex-based map configurations to ensure they are not vulnerable to this specific attack, which relies on a specific pattern of usage that can be exploited by an attacker with sufficient knowledge and resources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
37.0.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-9256CVE-2026-9256
CVE-2026-42945CVE-2026-42945
CVE-2026-42533CVE-2026-42533
Target & Sectors
Global Scope
Incident Timeline
July 15
Threat actors exploited a previously unknown vulnerability in NGINX, compromising the security of any system running an earlier version.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-42533
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
organisation
NGINX
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
infrastructure
1.30.4
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
infrastructure
1.31.3
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
infrastructure
37.0.3
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
observable
37.0.3.1
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
July 20
Threat actors used a known exploit of CVE-2026-42533 to target an unknown entity on July 20.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-42533
As of July 20, CVE-2026-42533 was not on CISA's
Known Exploited Vulnerabilities catalog
and no public exploit code had appeared.
attribution
CVE-2026
As of July 20, CVE-2026-42533 was not on CISA's
Known Exploited Vulnerabilities catalog
and no public exploit code had appeared.
attribution
Known Exploited
As of July 20, CVE-2026-42533 was not on CISA's
Known Exploited Vulnerabilities catalog
and no public exploit code had appeared.
tactic
T1588.006 - Vulnerabilities
As of July 20, CVE-2026-42533 was not on CISA's
Known Exploited Vulnerabilities catalog
and no public exploit code had appeared.
2026/07/20
A reader of the F5 advisory could reasonably conclude this is DoS-only on default systems. The fix is to upgrade to nginx 1.30.4 or 1.31.3, or NGINX Plus 37.0.3.1.
Click on any entity below to view its context and source!
organisation
CVE-2026
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers.
organisation
CVE-2026-42533
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
infrastructure
9.2
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
organisation
NGINX Plus and Open Source
CVE-2026-42533
affects NGINX Plus and Open Source when specific regex-based map configurations are used.
organisation
Shaw
While F5 highlights denial-of-service risks, Shaw believes the flaw could also help attackers bypass ASLR protections and achieve remote code execution under certain conditions.
F5 conditions code execution on ASLR being disabled or bypassable, and Shaw's argument is that the flaw supplies the bypass itself.
infrastructure
0.9.6
The vulnerability affects NGINX versions from 0.9.6 through 1.31.2.
Every nginx version from
0.9.6 through 1.31.2
is vulnerable, a range that reaches back to 2011, when
map
gained regex support.
infrastructure
1.31.2
The vulnerability affects NGINX versions from 0.9.6 through 1.31.2.
Every nginx version from
0.9.6 through 1.31.2
is vulnerable, a range that reaches back to 2011, when
map
gained regex support.
organisation
NGINX
The vulnerability affects NGINX versions from 0.9.6 through 1.31.2.
The overflow lives in nginx's script engine, the code that assembles strings from directives at request time.
infrastructure
1.30.4
F5 fixed the issue in NGINX 1.30.4, 1.31.3 and NGINX Plus 37.0.3.1.
infrastructure
1.31.3
F5 fixed the issue in NGINX 1.30.4, 1.31.3 and NGINX Plus 37.0.3.1.
infrastructure
37.0.3
F5 fixed the issue in NGINX 1.30.4, 1.31.3 and NGINX Plus 37.0.3.1.
organisation
Winfunc Research
The researchers Mufeed VH of Winfunc Research and Maxim Dounin discovered the vulnerability.
nginx's own changelog credits the fix to Mufeed VH of Winfunc Research and to maintainer Maxim Dounin.
organisation
Mufeed
nginx's own changelog credits the fix to Mufeed VH of Winfunc Research and to maintainer Maxim Dounin.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, F5)
infrastructure
24.04
He told The Hacker News that the capture clobbering also runs in reverse: when the clobbered capture is smaller than the original, the oversized buffer hands back uninitialised heap data, and on a default Ubuntu 24.04 build a single unauthenticated GET recovers the addresses a payload needs.
organisation
The Hacker News
He told The Hacker News that the capture clobbering also runs in reverse: when the clobbered capture is smaller than the original, the oversized buffer hands back uninitialised heap data, and on a default Ubuntu 24.04 build a single unauthenticated GET recovers the addresses a payload needs.
organisation
NGINX Ingress Controller, Gateway Fabric
F5's
advisory
lists the flaw as affecting NGINX Ingress Controller, Gateway Fabric, App Protect WAF, and Instance Manager alongside the core server and NGINX Plus, though at publication F5 had not listed fixed builds for those four products.
organisation
NGINX Plus
F5's
advisory
lists the flaw as affecting NGINX Ingress Controller, Gateway Fabric, App Protect WAF, and Instance Manager alongside the core server and NGINX Plus, though at publication F5 had not listed fixed builds for those four products.
organisation
CVSS
F5 scores it 9.2 on CVSS v4 and 8.1 on the older v3.1 scale, and rates attack complexity high.
organisation
DoS
"A reader of the F5 advisory could reasonably conclude this is DoS-only on default systems.
organisation
F5
But he told The Hacker News the mitigation leaves a narrower path open: a
map
that defines the same named group as the location regex reaches the same overflow through a second code path, which he confirmed with AddressSanitizer and which F5's advisory does not mention.
organisation
Rift
The trigger differs, a stale flag in Rift, overlapping captures in the rewrite bug, clobbered capture state here.
financial
$1 $ numbered capture
The exposure to grep for is narrow: a regex-based
map
whose variable appears in a string expression alongside a numbered capture (
$1
,
$2
) from an earlier regex, with the capture written ahead of the map variable.
2026/08/09
Shaw announced he would publish his proof-of-concept 21 days after the patch.
Tactical Metrics
Metrics
infrastructure
9.2
Software Version
Click for context!
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
Metrics
infrastructure
0.9.6
Software Version
The vulnerability affects NGINX versions from 0.9.6 through 1.31.2.
Every nginx version from
0.9.6 through 1.31.2
is vulnerable, a range that reaches back to 2011, when
map
gained regex support.
Metrics
infrastructure
1.31.2
Software Version
The vulnerability affects NGINX versions from 0.9.6 through 1.31.2.
Every nginx version from
0.9.6 through 1.31.2
is vulnerable, a range that reaches back to 2011, when
map
gained regex support.
Metrics
infrastructure
1.30.4
Software Version
F5 fixed the issue in NGINX 1.30.4, 1.31.3 and NGINX Plus 37.0.3.1.
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Metrics
infrastructure
1.31.3
Software Version
F5 fixed the issue in NGINX 1.30.4, 1.31.3 and NGINX Plus 37.0.3.1.
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Metrics
infrastructure
37.0.3
Software Version
F5 fixed the issue in NGINX 1.30.4, 1.31.3 and NGINX Plus 37.0.3.1.
CVE-2026-42533
was patched on July 15 in
nginx 1.30.4 (stable) and 1.31.3 (mainline)
, and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Metrics
infrastructure
24.04
Software Version
…bbering also runs in reverse: when the clobbered capture is smaller than the original, the oversized buffer hands back uninitialised heap data, and on a default Ubuntu 24.04 build a single unauthenticated GET recovers the addresses a payload needs.
Metrics
financial
1
$ Numbered Capture
The exposure to grep for is narrow: a regex-based
map
whose variable appears in a string expression alongside a numbered capture (
$1
,
$2
) from an earlier regex, with the capture written ahead of the map variable.
Intelligence Sources
Security Affairs
2026-07-20
The Hacker News
2026-07-19
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-21T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
organisation
Identified Entity
CVE-2026
entity
7x
infrastructure
Software Version
9.2
version
5x
timeline
Temporal Reference
July 15
date
3x
vulnerability
Exploited CVE
CVE-2026-42533
cve
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
attribution
Attributing Entity
CVE-2026
authority
2x
general metric
F5
9
f5
Contextual Telemetry
Context Block
4 METRICS
vulnerability
CVSS Score
9
score
general metric
Ubuntu
24
ubuntu
general metric
V4
8
v4
financial
$ Numbered Capture
1
$ numbered capture
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.