15-year-old NGINX vulnerability lets attackers crash workers and achieve remote code execution; critical pre-auth RCE flaw (CVE-2026-42533) found
Stan ShawMaxim DouninF5, Inc.nginx

15-year-old NGINX vulnerability lets attackers crash workers and achieve remote code execution; critical pre-auth RCE flaw (CVE-2026-42533) found

A critical pre-authentication remote code execution vulnerability (CVE-2026-42533) in NGINX, affecting versions 0.9.6 to 1.30.3, allows attackers to exploit regex patterns to achieve remote code execution. The flaw has been present since 2011 and was reported by researcher Stan Shaw to F5 SIRT.

CyberSecurityNews CyberSecurityNews+1 source23h ago
CuriousCats Full Story

A critical pre-authentication remote code execution vulnerability (CVE-2026-42533) in NGINX has been discovered, allowing attackers to exploit regex patterns to achieve reliable RCE without authentication. This flaw, present since March 2011, stems from a missing save-and-restore mechanism for PCRE capture state within nginx’s two-pass script evaluation engine.56

The vulnerability affects nginx versions 0.9.6 through 1.30.3 (stable) and 1.31.2 (mainline), with patched releases including 1.30.4 and 1.31.3. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated the fix. The flaw enables attackers to trigger a heap buffer overflow and expose heap pointers through an information leak, defeating Address Space Layout Randomization (ASLR).34

The vulnerability is particularly concerning as it allows for reliable RCE using just one leak request, approximately 40 spray connections, and one overflow-triggering request, achieving a success rate of 10/10 on Ubuntu 24.04 with full ASLR enabled. Affected configurations include regex captures with regex map variables in the same evaluation path, impacting both HTTP and stream modules.

Administrators are urged to upgrade immediately to the patched versions and audit their configurations. The researcher has also released a static configuration scanner to help identify vulnerable setups without exploitation. A proof-of-concept exploit will be withheld for 21 days post-patch release to allow time for updates, following rapid weaponization seen in previous vulnerabilities.7910

Key Insight
“The flaw has been silently exploitable since March 2011 when the map directive gained regex support, and patch releases include nginx 1.30.4, 1.31.3, and corresponding NGINX Plus updates. A static configuration scanner has been released to help administrators audit vulnerable setups without triggering the exploit.”
CuriousCats studied:
1
CyberSecurityNewsCyberSecurityNews
“A newly disclosed flaw tracked as nginx’s script engine and has been silently exploitable since March 2011, when the `map` directive gained regex support.”
CyberSecurityNews →
2
The Cyber ExpressThe Cyber Express
“A newly disclosed security flaw, CVE-2026-42533, has revealed a critical Pre-Auth nginx vulnerability that could allow attackers to achieve reliable RCE (remote code execution) without authentication.”
The Cyber Express →
Ask CuriousCats
What is the NGINX vulnerability?
Who discovered the CVE-2026-42533 flaw?
Why is this vulnerability critical?
Are patches available for all NGINX versions?
How does it compare to other RCE vulnerabilities?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats