Critical nginx heap overflow allows remote crashes
🛡️ F5 released patches for a critical nginx heap buffer overflow (CVE-2026-42533) that can crash or restart worker processes and, in some environments, enable remote code execution. Fixed versions are nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1; systems on earlier releases should upgrade. The flaw occurs in the nginx script engine when a regex-based map's output variable is used in a string expression after an earlier regex capture, causing a two-pass evaluation mismatch that leads to overruns. F5 scores the flaw 9.2 (CVSS v4) and notes exposure depends on configuration rather than version alone.
