CVE-2026-42533
Description
A flaw was found in NGINX. An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests when the map directive uses regular expression (regex) matching and references regex capture variables before referencing the map output variable. This can lead to a heap buffer overflow, which may allow for arbitrary code execution on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. Additionally, this flaw can cause a denial-of-service (DoS) due to the NGINX worker process restarting.
Statement
This vulnerability in NGINX allows a remote, unauthenticated attacker to trigger a heap buffer overflow, leading to a denial of service (Dos). This occurs when the map directive uses regex matching and references regex capture variables before the map output variable. While arbitrary code execution is a theoretical risk, it is significantly reduced on Red Hat systems where Address Space Layout Randomization (ASLR) is enabled by default.
Mitigation
To mitigate this vulnerability, do not use unnamed captures. Use named captures instead and only use them in the same block with the regex match.
Red Hat recommends updating nginx to the latest version when a fix is available.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7 | N/A | 8.1 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | Low | N/A | High |
| Integrity Impact | Low | N/A | High |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Red Hat CVSS v3 Score Explanation
Adjusted from upstream C:H/I:H/A:H (8.1) to C:L/I:L/A:H (7.0). C:L/I:L: code execution requires ASLR disabled or bypassed — ASLR is enabled by default on all RHEL systems, making RCE unlikely; bounded to low. A:H: sustained crafted requests can keep crashing nginx worker processes, causing meaningful service disruption despite auto-restart.
Understanding the Weakness (CWE)
Integrity,Availability,Confidentiality
Technical Impact: DoS: Crash, Exit, or Restart; Execute Unauthorized Code or Commands; Read Memory; Modify Memory
If the incorrect calculation is used in the context of memory allocation, then the software may create a buffer that is smaller or larger than expected. If the allocated buffer is smaller than expected, this could lead to an out-of-bounds read or write (CWE-119), possibly causing a crash, allowing arbitrary code execution, or exposing sensitive data.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.