Skip to content
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests. “heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affect...
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers | Huntaegis