NGINX released versions 1.31.3 and 1.30.4 to fix three security vulnerabilities affecting both NGINX Open Source and F5 NGINX Plus. The most severe issue, CVE-2026-42533, affects configurations using the map directive with regex matching in unsafe expression patterns and can be triggered by a crafted HTTP request from an unauthenticated attacker. F5 said the flaw can cause a heap buffer overflow in the worker process, leading to denial of service through worker restarts and, in environments where protections such as ASLR are disabled or bypassed, possible remote code execution. The issue is limited to the data plane, with no reported control plane exposure.
The updates also address CVE-2026-60005 in ngx_http_slice_module, where unauthenticated requests or background cache updates can trigger uninitialized memory access when the slice directive and unnamed regex captures are used, causing limited memory disclosure or worker crashes. A third flaw, CVE-2026-56434, affects ngx_http_ssi_module when SSI, proxy_pass, and proxy_buffering off are combined, allowing an attacker with man-in-the-middle control over upstream responses to trigger a heap buffer over-read that may restart the worker process or enable limited memory modification. The release additionally includes hardening and functional changes, including XML external entity controls for ngx_http_xslt_filter_module, new socket buffer directives, and HTTP/2 buffer handling improvements.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A report provided new technical details on CVE-2026-42533, describing how improper save/restore of PCRE capture state in nginx’s internal script engine can create both a heap buffer overflow and information leak that can be chained to unauthenticated RCE. The report also said the bug has reportedly been exploitable since March 2011, identified a named-capture variant, and noted release of a static configuration scanner while full exploit details were withheld for 21 days after the patch.
CVE-2026-56434 was disclosed as a heap buffer over-read in ngx_http_ssi_module affecting F5 NGINX Plus and NGINX Open Source. An unauthenticated attacker with man-in-the-middle control over upstream responses can trigger the flaw when SSI, proxy_pass, and proxy_buffering off are configured, potentially causing limited memory modification or worker restart.
CVE-2026-60005 was disclosed as an uninitialized memory access flaw in ngx_http_slice_module affecting F5 NGINX Plus and NGINX Open Source. Unauthenticated requests can trigger memory disclosure or worker process restart when the slice directive and unnamed regex captures are configured, or during a background cache update.
A vulnerability tracked as CVE-2026-42533 was disclosed affecting F5 NGINX Plus and NGINX Open Source when the map directive uses regex matching in unsafe expression patterns. Crafted HTTP requests can trigger a heap buffer overflow in the worker process, causing denial of service and potentially code execution under certain conditions.
NGINX released version 1.31.3 and the stable branch update 1.30.4 to fix three security issues: CVE-2026-42533, CVE-2026-60005, and CVE-2026-56434. The updates also included several non-security changes such as XSLT XXE controls and HTTP/2 buffer handling improvements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
24 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcethecyberexpress.com
Open sourcethecybersecguru.com
Open sourcegithub.com
Open sourcecyberstan.co.uk
Open sourcenginx.org
Open sourcenginx.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.