CVE-2026-42533

HIGH

F5 NGINX Plus - NGINX Map Directive and Regex Matching Vulnerability

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2026-42533. PoCs published by 0xCyberstan, gagaltotal, seguridadentrerios.

AI-analyzed exploit summary This tool statically analyzes nginx configurations to detect preconditions for CVE-2026-42533, a two-pass capture-clobbering bug in nginx's complex_value buffer handling. The vulnerability arises when regex captures and map variables share a buffer, leading to heap overflows or uninitialized heap disclosures. The scanner does not exploit the vulnerability but identifies vulnerable configurations.

Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Exploits (7)

nomisec SCANNER 1 stars
by 0xCyberstan · poc
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

This tool statically analyzes nginx configurations to detect preconditions for CVE-2026-42533, a two-pass capture-clobbering bug in nginx's complex_value buffer handling. The vulnerability arises when regex captures and map variables share a buffer, leading to heap overflows or uninitialized heap disclosures. The scanner does not exploit the vulnerability but identifies vulnerable configurations.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: nginx (versions affected by CVE-2026-42533)
No auth needed
Prerequisites: Access to nginx configuration files · Vulnerable nginx version with specific regex capture and map variable patterns in configuration
mistral-large-3 · analyzed Jul 17, 2026 Full analysis →
github SCANNER
by gagaltotal · gopoc
https://github.com/gagaltotal/CVE-2026-42533-nginx

This repository contains a Go-based static analysis tool that scans nginx configuration files for patterns vulnerable to CVE-2026-42533, a complex_value two-pass capture-clobbering issue leading to heap out-of-bounds writes or information disclosure. The tool parses configurations to detect risky regex captures and map variable interactions without exploiting the vulnerability.

Classification
Scanner 98%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: nginx (versions affected by CVE-2026-42533)
No auth needed
Prerequisites: Access to nginx configuration files · Go 1.21+ for building the scanner
mistral-large-3 · analyzed Jul 23, 2026 Full analysis →
github SCANNER
by seguridadentrerios · shellpoc
https://github.com/seguridadentrerios/CVE-2026-42533

This Bash script checks for potential exposure to CVE-2026-42533 in NGINX by verifying the installed version and scanning configuration files for vulnerable 'map' directives and regex patterns. It does not exploit the vulnerability but identifies at-risk configurations.

Classification
Scanner 99%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: NGINX versions prior to 1.30.4
No auth needed
Prerequisites: NGINX installed on the target system · Read access to /etc/nginx configuration files
mistral-large-3 · analyzed Jul 22, 2026 Full analysis →
nomisec SCANNER
by seguridadentrerios · poc
https://github.com/seguridadentrerios/CVE-2026-42533-

This Bash script checks for potential exposure to CVE-2026-42533 in NGINX by verifying the installed version and scanning configuration files for vulnerable 'map' directives and regex patterns. It does not exploit the vulnerability but identifies at-risk configurations.

Classification
Scanner 99%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: NGINX versions prior to 1.30.4
No auth needed
Prerequisites: NGINX installed on the target system · Read access to /etc/nginx configuration files
mistral-large-3 · analyzed Jul 22, 2026 Full analysis →
nomisec STUB
by Daniyal48 · poc
https://github.com/Daniyal48/ghostlock-vagrant-box

This repository provides a Vagrant-based testbed environment for demonstrating a two-stage exploit chain involving CVE-2026-42533 (Nginx PCRE RCE) and CVE-2026-43449 (Linux kernel LPE). It includes detailed technical documentation and provisioning scripts but no actual exploit code.

Classification
Stub 95%
Attack Type
Rce | Lpe
Complexity
Moderate
Reliability
Theoretical
Target: Nginx (CVE-2026-42533), Linux kernel (CVE-2026-43449)
No auth needed
Prerequisites: Vagrant and VMware Desktop installed · Isolated lab environment · Exploit code for CVE-2026-42533 and CVE-2026-43449 (not provided in repo)
mistral-large-3 · analyzed Jul 20, 2026 Full analysis →
nomisec SCANNER
by srkyn · poc
https://github.com/srkyn/nginx-map-risk-audit

This repository provides a defensive heuristic scanner for CVE-2026-42533, a vulnerability in NGINX related to regex map patterns with captures that could lead to buffer overflow or worker crashes. The tool audits NGINX configurations to identify risky patterns but does not exploit the vulnerability.

Classification
Scanner 98%
Attack Type
Dos
Complexity
Moderate
Reliability
Theoretical
Target: NGINX (versions likely affected by CVE-2026-42533, specific version not stated)
No auth needed
Prerequisites: Access to NGINX configuration files · Regex map patterns with captures in NGINX configs
mistral-large-3 · analyzed Jul 20, 2026 Full analysis →
nomisec SCANNER
by 0xCyberstan · poc
https://github.com/0xCyberstan/CVE-2026-42533-Scanner

This tool statically analyzes nginx configurations to detect preconditions for CVE-2026-42533, a two-pass capture-clobbering bug in nginx's complex_value buffer handling. The vulnerability arises when regex captures and map variables share a buffer, leading to heap overflows or uninitialized heap disclosures. The scanner flags vulnerable configurations but does not exploit them.

Classification
Scanner 100%
Attack Type
Info Leak | Dos
Complexity
Moderate
Reliability
Reliable
Target: nginx (versions affected by CVE-2026-42533)
No auth needed
Prerequisites: Access to nginx configuration files · Vulnerable nginx version with specific regex capture and map variable patterns in the same two-pass buffer
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://my.f5.com/manage/s/article/K000162097

Scores

CVSS v3 8.1
EPSS 0.0083
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (5)
F5/NGINX Open Source 0.9.6 - 1.30.4
F5/NGINX Open Source 1.31.2 - 1.31.3
F5/NGINX Plus 37.0.0.1 - 37.0.3.1
F5/NGINX Plus R33
F5/NGINX Plus R36 - R36 P7
Published Jul 15, 2026
Tracked Since Jul 15, 2026