Critical security vulnerability: Malicious code can slip onto Nginx servers
Attackers can target Nginx Open Source and Nginx Plus. Security updates are available.
(Image: AFANASEV IVAN/Shutterstock.com)
The web server software Nginx is vulnerable. Admins should install the repaired versions promptly. So far, there are no indications of attacks from the network equipment manufacturer F5. However, because the hurdles for a successful attack are not very high, this could change quickly. Therefore, admins should not delay patching for too long.
DoS and malicious code attacks possible
As indicated in a warning message, the security vulnerability (CVE-2026-42533) is classified as “critical.” It is located in the map directive tool for variable assignment in the context of processing regular expressions (Regex) and variables. Remote attackers without authentication can exploit this to trigger memory errors (heap buffer overflow) with prepared HTTP requests.
If such an attack is successful, it will lead to crashes (DoS). If the Address Space Layout Randomization (ASLR) protection mechanism is deactivated or if attackers can bypass it, malicious code can reach systems and compromise them.
Install security update
In the security section of the Nginx website, the developers write that versions 0.9.6 up to and including 1.31.2 are affected. They state that they have closed the vulnerability in **versions 1.31.3 and 1.30.4**.
Videos by heise
In addition, F5 lists the versions of its repaired software products that have implemented the current Nginx versions. However, not all products are apparently secured yet, and the security update for Nginx App Protect WAF, among others, is still pending.
- Nginx Plus 37.0.3.1, R36 P7
- Nginx Open Source 1.31.3, 1.30.4
- Nginx Instance Manager pending
- F5 WAF for Nginx 5.13.4
- Nginx App Protect WAF pending
- Nginx Gateway Fabric 2.6.7
- Nginx Ingress Controller 2026-lts-r4
5.5.3
(des)