Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.

Triggering it can crash or restart the worker, causing a denial of

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

US hires over 2k video gamers as air traffic controllers

US hires over 2k video gamers as air traffic controllers Source: Hacker News

Eight Myths on Software Engineering and GenAI

Eight Myths on Software Engineering and GenAI Source: Hacker News

The founder of Craigslist has given away half a billion dollars

The founder of Craigslist has given away half a billion dollars Source: Hacker News