Crypto Ticker:
sysadmin from Cyber Security News

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

Guru Baran
21 hours ago
8 Views
0 Comments
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx 1.30.4 (stable) and 1.31.3 (mainline), along with corresponding patches for NGINX Plus R33–R36 (fixed in R36 P7) and 37.0.0.1–37.0.2.1 (fixed in 37.0.3.1). The vulnerability is a pre-authentication remote code execution flaw rooted in a missing save/restore of PCRE capture state in nginx’s internal script engine. nginx evaluates expressions in two passes a LEN pass to measure buffer size and a VALUE pass to write the actual data, and both...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!