High CVE-2026-42533, CVE-2026-42945 — A heap buffer overflow in nginx's map directive can be triggered by unauthenticated HTTP requests, crashing workers or running code. Affects nginx 0.9.6 through 1.31.2. Fixed versions, config check, and Debian packages.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If your nginx config has a map with a regex and something uses that regex's capture variables ($1, named captures) before the map's own output, a crafted request can overflow the worker's heap. Usually that's a crash and restart (DoS); with ASLR bypassed it's code execution. Upgrade to nginx 1.30.4+ / 1.31.3+ or your distro's patched package.
| CVE | CVE-2026-42533 (plus related CVE-2026-42945 in the rewrite module) |
|---|---|
| Component | nginx map directive with regex matching |
| Type | Heap buffer overflow in the worker process |
| CVSS | 3.1: 8.1 High · 4.0: 9.2 Critical · nginx.org rates it “major” |
| Auth needed | None: remote, unauthenticated HTTP requests |
| Affected | nginx open source 0.9.6 – 1.31.2; NGINX Plus R33 – R36 P6, 37.0.0.1 – 37.0.3.0 |
| Fixed in | nginx 1.30.4 / 1.31.3; Debian 12 1.22.1-9+deb12u10; Debian 13 1.26.3-3+deb13u8 |
| Published | 2026-07-15 |
nginx’s map directive builds a variable from another one, often using regexes:
map $request_uri $backend {
~^/api/(?<ver>v[0-9]+)/ api_$ver;
default web;
}
The overflow happens when a string expression references the map’s regex capture variables before the map’s output variable, so the captures get read before the map has filled them in. F5 also notes the same overflow can be reached through a non-cacheable variable in a string expression under certain conditions. A crafted request then makes the worker write past a heap buffer.
Most of the time the worker crashes and the master starts a new one, so an attacker can knock your site over repeatedly. On systems with ASLR disabled, or where the attacker can bypass it, F5 says code execution as the nginx worker user is possible.
First, the version:
nginx -v
dpkg -l nginx nginx-core 2>/dev/null | grep ^ii # Debian/Ubuntu
rpm -q nginx 2>/dev/null # RHEL/Fedora
docker ps --format '{{.Image}}' | grep -i nginx # containers
Then, whether your config uses the pattern. Look for map blocks with regex entries (a ~ or ~* prefix):
nginx -T 2>/dev/null | grep -nA6 '^\s*map ' | grep -E '~\*?'
No regex maps means the main bug isn’t reachable on your config, but upgrade anyway. The same releases fix several other memory bugs (below), and configs change.
Using Caddy, Traefik, or HAProxy instead? This CVE doesn’t apply to you. It’s nginx code. Check nginx-based images too, though: many Docker apps and “proxy manager” UIs ship nginx inside.
| Source | Upgrade to |
|---|---|
| nginx.org mainline | 1.31.3 or later (1.31.6+ also fixes the later HTTP/3 bug CVE-2026-90439) |
| nginx.org stable | 1.30.4 or later (1.30.5+ for CVE-2026-90439) |
| Debian 12 bookworm | 1.22.1-9+deb12u10 (DLA-4784-1) |
| Debian 13 trixie | 1.26.3-3+deb13u8 or later (DSA-6496-1) |
Docker nginx image | Pull the current tag and recreate the container |
# Debian/Ubuntu
apt update && apt install --only-upgrade nginx nginx-core
nginx -t && systemctl reload nginx
# Docker Compose
docker compose pull && docker compose up -d
A reload is enough after upgrading the package. nginx swaps workers without dropping connections.
map’s capture variables in string expressions; that is the vulnerable pattern.cat /proc/sys/kernel/randomize_va_space should print 2). That moves the worst case from code execution to crashes.nginx has had an unusually busy 2026. Upgrading to 1.30.4 / 1.31.3 also fixes CVE-2026-60005 (memory disclosure in slice) and CVE-2026-56434 (use-after-free in ssi). It also includes the May fix for CVE-2026-42945, a similar heap overflow in the rewrite module when a rewrite with an unnamed capture ($1) and a ? in the replacement is followed by another rewrite, if, or set (fixed in 1.30.1 / 1.31.0).
Repeated worker crashes are the main sign:
grep -E 'worker process [0-9]+ exited on signal (11|6)' /var/log/nginx/error.log
journalctl -u nginx | grep -i 'signal 11'
A burst of signal 11 (segfault) exits that lines up with odd request URIs in the access log is worth investigating.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.