Vulnerability Details CVE-2026-42533
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.035
EPSS Ranking 88.2%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-42533
-
cpe:2.3:a:f5:nginx_gateway_fabric:1.3.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:1.4.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:1.5.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:1.5.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:1.6.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:1.6.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:1.6.2
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.0.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.0.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.0.2
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.1.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.1.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.1.2
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.1.3
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.1.4
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.2.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.2.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.2.2
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.3.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.4.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.4.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.4.2
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.5.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.5.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.6.0
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.6.1
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.6.2
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.6.3
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.6.4
-
cpe:2.3:a:f5:nginx_gateway_fabric:2.6.5
-
cpe:2.3:a:f5:nginx_ingress_controller:2026-lts-r1
-
cpe:2.3:a:f5:nginx_ingress_controller:2026-lts-r2
-
cpe:2.3:a:f5:nginx_ingress_controller:2026-lts-r3
-
cpe:2.3:a:f5:nginx_ingress_controller:3.5.0
-
cpe:2.3:a:f5:nginx_ingress_controller:3.5.1
-
cpe:2.3:a:f5:nginx_ingress_controller:3.5.2
-
cpe:2.3:a:f5:nginx_ingress_controller:3.6.0
-
cpe:2.3:a:f5:nginx_ingress_controller:3.6.1
-
cpe:2.3:a:f5:nginx_ingress_controller:3.6.2
-
cpe:2.3:a:f5:nginx_ingress_controller:3.7.0
-
cpe:2.3:a:f5:nginx_ingress_controller:3.7.1
-
cpe:2.3:a:f5:nginx_ingress_controller:3.7.2
-
cpe:2.3:a:f5:nginx_ingress_controller:4.0.0
-
cpe:2.3:a:f5:nginx_ingress_controller:4.0.1
-
cpe:2.3:a:f5:nginx_ingress_controller:5.0.0
-
cpe:2.3:a:f5:nginx_ingress_controller:5.3.0
-
cpe:2.3:a:f5:nginx_ingress_controller:5.3.2
-
cpe:2.3:a:f5:nginx_ingress_controller:5.3.3
-
cpe:2.3:a:f5:nginx_ingress_controller:5.3.4
-
cpe:2.3:a:f5:nginx_ingress_controller:5.4.0
-
cpe:2.3:a:f5:nginx_ingress_controller:5.4.1
-
cpe:2.3:a:f5:nginx_ingress_controller:5.4.2
-
cpe:2.3:a:f5:nginx_ingress_controller:5.4.3
-
cpe:2.3:a:f5:nginx_ingress_controller:5.5.0
-
cpe:2.3:a:f5:nginx_ingress_controller:5.5.1
-
cpe:2.3:a:f5:nginx_ingress_controller:5.5.2
-
cpe:2.3:a:f5:nginx_plus:37.0.0.1
-
cpe:2.3:a:f5:nginx_plus:37.0.1.1
-
cpe:2.3:a:f5:nginx_plus:37.0.2.1
-
cpe:2.3:a:f5:nginx_plus:r33
-
cpe:2.3:a:f5:nginx_plus:r34
-
cpe:2.3:a:f5:nginx_plus:r35
-
cpe:2.3:a:f5:nginx_plus:r36
-
F5
»
Waf
»
Version: 4.11.0
-
F5
»
Waf
»
Version: 4.12.0
-
F5
»
Waf
»
Version: 4.13.0
-
F5
»
Waf
»
Version: 4.14.0
-
F5
»
Waf
»
Version: 4.15.0
-
F5
»
Waf
»
Version: 4.16.0
-
F5
»
Waf
»
Version: 5.10.0
-
F5
»
Waf
»
Version: 5.11.0
-
F5
»
Waf
»
Version: 5.11.1
-
F5
»
Waf
»
Version: 5.12.0
-
F5
»
Waf
»
Version: 5.12.1
-
F5
»
Waf
»
Version: 5.13.0
-
F5
»
Waf
»
Version: 5.13.1
-
F5
»
Waf
»
Version: 5.13.2
-
F5
»
Waf
»
Version: 5.13.3
-
F5
»
Waf
»
Version: 5.2.0
-
F5
»
Waf
»
Version: 5.3.0
-
F5
»
Waf
»
Version: 5.4.0
-
F5
»
Waf
»
Version: 5.5.0
-
F5
»
Waf
»
Version: 5.6.0
-
F5
»
Waf
»
Version: 5.7.0
-
F5
»
Waf
»
Version: 5.8.0
-
F5
»
Waf
»
Version: 5.9.0