Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CVE-2026-42533: nginx map + regex Heap Overflow (Crash or Remote Code Execution)

High CVE-2026-42533, CVE-2026-42945 — A heap buffer overflow in nginx's map directive can be triggered by unauthenticated HTTP requests, crashing workers or running code. Affects nginx 0.9.6 through 1.31.2. Fixed versions, config check, and Debian packages.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If your nginx config has a map with a regex and something uses that regex's capture variables ($1, named captures) before the map's own output, a crafted request can overflow the worker's heap. Usually that's a crash and restart (DoS); with ASLR bypassed it's code execution. Upgrade to nginx 1.30.4+ / 1.31.3+ or your distro's patched package.

CVECVE-2026-42533 (plus related CVE-2026-42945 in the rewrite module)
Componentnginx map directive with regex matching
TypeHeap buffer overflow in the worker process
CVSS3.1: 8.1 High · 4.0: 9.2 Critical · nginx.org rates it “major”
Auth neededNone: remote, unauthenticated HTTP requests
Affectednginx open source 0.9.6 – 1.31.2; NGINX Plus R33 – R36 P6, 37.0.0.1 – 37.0.3.0
Fixed innginx 1.30.4 / 1.31.3; Debian 12 1.22.1-9+deb12u10; Debian 13 1.26.3-3+deb13u8
Published2026-07-15

What the bug is

nginx’s map directive builds a variable from another one, often using regexes:

map $request_uri $backend {
    ~^/api/(?<ver>v[0-9]+)/   api_$ver;
    default                     web;
}

The overflow happens when a string expression references the map’s regex capture variables before the map’s output variable, so the captures get read before the map has filled them in. F5 also notes the same overflow can be reached through a non-cacheable variable in a string expression under certain conditions. A crafted request then makes the worker write past a heap buffer.

Most of the time the worker crashes and the master starts a new one, so an attacker can knock your site over repeatedly. On systems with ASLR disabled, or where the attacker can bypass it, F5 says code execution as the nginx worker user is possible.

Am I affected?

First, the version:

nginx -v
dpkg -l nginx nginx-core 2>/dev/null | grep ^ii      # Debian/Ubuntu
rpm -q nginx 2>/dev/null                             # RHEL/Fedora
docker ps --format '{{.Image}}' | grep -i nginx      # containers

Then, whether your config uses the pattern. Look for map blocks with regex entries (a ~ or ~* prefix):

nginx -T 2>/dev/null | grep -nA6 '^\s*map ' | grep -E '~\*?'

No regex maps means the main bug isn’t reachable on your config, but upgrade anyway. The same releases fix several other memory bugs (below), and configs change.

Using Caddy, Traefik, or HAProxy instead? This CVE doesn’t apply to you. It’s nginx code. Check nginx-based images too, though: many Docker apps and “proxy manager” UIs ship nginx inside.

How to patch

SourceUpgrade to
nginx.org mainline1.31.3 or later (1.31.6+ also fixes the later HTTP/3 bug CVE-2026-90439)
nginx.org stable1.30.4 or later (1.30.5+ for CVE-2026-90439)
Debian 12 bookworm1.22.1-9+deb12u10 (DLA-4784-1)
Debian 13 trixie1.26.3-3+deb13u8 or later (DSA-6496-1)
Docker nginx imagePull the current tag and recreate the container
# Debian/Ubuntu
apt update && apt install --only-upgrade nginx nginx-core
nginx -t && systemctl reload nginx

# Docker Compose
docker compose pull && docker compose up -d

A reload is enough after upgrading the package. nginx swaps workers without dropping connections.

If you can’t upgrade yet

  • Check F5’s advisory (K000162097) for the official mitigation for your config. Until then, avoid using a regex map’s capture variables in string expressions; that is the vulnerable pattern.
  • Make sure ASLR is on (cat /proc/sys/kernel/randomize_va_space should print 2). That moves the worst case from code execution to crashes.
  • Put a CDN or WAF in front to absorb crash-loop attempts. It won’t fix the bug.

nginx has had an unusually busy 2026. Upgrading to 1.30.4 / 1.31.3 also fixes CVE-2026-60005 (memory disclosure in slice) and CVE-2026-56434 (use-after-free in ssi). It also includes the May fix for CVE-2026-42945, a similar heap overflow in the rewrite module when a rewrite with an unnamed capture ($1) and a ? in the replacement is followed by another rewrite, if, or set (fixed in 1.30.1 / 1.31.0).

Detecting exploitation

Repeated worker crashes are the main sign:

grep -E 'worker process [0-9]+ exited on signal (11|6)' /var/log/nginx/error.log
journalctl -u nginx | grep -i 'signal 11'

A burst of signal 11 (segfault) exits that lines up with odd request URIs in the access log is worth investigating.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories