Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.

Triggering it can crash or restart the worker, causing a denial of

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a

Launch HN: Almanac (YC S26) – AI that knows your company

Launch HN: Almanac (YC S26) – AI that knows your company Source: Hacker News

Guerrilla London Bus Ads Mock Kylie Jenner’s Meta Glasses Campaign

Guerrilla London Bus Ads Mock Kylie Jenner’s Meta Glasses Campaign Source: Hacker News