Critical security vulnerability: Malicious code can slip onto Nginx servers

Attackers can target Nginx Open Source and Nginx Plus. Security updates are available.

listen Print view
A symbolic update bar is filling up.

(Image: AFANASEV IVAN/Shutterstock.com)

2 min. read

The web server software Nginx is vulnerable. Admins should install the repaired versions promptly. So far, there are no indications of attacks from the network equipment manufacturer F5. However, because the hurdles for a successful attack are not very high, this could change quickly. Therefore, admins should not delay patching for too long.

As indicated in a warning message, the security vulnerability (CVE-2026-42533) is classified as “critical.” It is located in the map directive tool for variable assignment in the context of processing regular expressions (Regex) and variables. Remote attackers without authentication can exploit this to trigger memory errors (heap buffer overflow) with prepared HTTP requests.

If such an attack is successful, it will lead to crashes (DoS). If the Address Space Layout Randomization (ASLR) protection mechanism is deactivated or if attackers can bypass it, malicious code can reach systems and compromise them.

In the security section of the Nginx website, the developers write that versions 0.9.6 up to and including 1.31.2 are affected. They state that they have closed the vulnerability in **versions 1.31.3 and 1.30.4**.

Videos by heise

In addition, F5 lists the versions of its repaired software products that have implemented the current Nginx versions. However, not all products are apparently secured yet, and the security update for Nginx App Protect WAF, among others, is still pending.

  • Nginx Plus 37.0.3.1, R36 P7
  • Nginx Open Source 1.31.3, 1.30.4
  • Nginx Instance Manager pending
  • F5 WAF for Nginx 5.13.4
  • Nginx App Protect WAF pending
  • Nginx Gateway Fabric 2.6.7
  • Nginx Ingress Controller 2026-lts-r4
    5.5.3

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.