As cited
Copy frozen at (site build).
vulnerabilities
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 released patches for a critical nginx heap buffer overflow vulnerability (CVE-2026-42533) that allows unauthenticated remote attackers to crash worker processes with specially crafted HTTP requests. The flaw was patched on July 15, 2026 in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Exploitation can cause denial of service by restarting or crashing workers.
Why it matters: Organizations running nginx versions before 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 face immediate denial of service risk from unauthenticated attackers and should prioritize patching to restore stability.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 released patches for a critical nginx heap buffer overflow vulnerability (CVE-2026-42533) that allows unauthenticated remote attackers to crash worker processes with specially crafted HTTP requests. The flaw was patched on July 15, 2026 in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Exploitation can cause denial of service by restarting or crashing workers.
Why it matters: Organizations running nginx versions before 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 face immediate denial of service risk from unauthenticated attackers and should prioritize patching to restore stability.
- Source published
- First seen by Cybersecurity Tracker