CVE-2026-42934
published 2026-05-13CVE-2026-42934: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with…
PriorityP430medium4.8CVSS 3.1
AVNACHPRNUINSUCLINAL
EPSS
0.72%
50.0th percentile
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_open_source | >= 0.3.50 < 1.30.1 | 1.30.1 |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R32 < R32 P6 | R32 P6 |
| f5 | nginx_plus | >= R36 < R36 P4 | R36 P4 |
| insights-proxy | insights-proxy-container-rhel9 | — | — |
| nginx_1.24 | nginx | — | — |
| nginx_1.26 | nginx | — | — |
| ubuntu | nginx | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu6.9MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-03·CVSS 6.3
CVE-2026-1642 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that the nginx ngx_mail_smtp_module module incorrectly
handled certain memory operations when doing SMTP authentication. This
could possibly result in sensitive information being sent to the
authentication server. (CVE-2025-53859)
It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server. (CVE-2026-1642)
It was discovered that the nginx ngx_mail_auth_http_module module
incorrectly handled certain requests. An attacker could possibly use this
issue to cause nginx to crash, resulting in a denial of service.
(CVE-2026-27651)
It was discovered that
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 6.9
CVE-2026-9256 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx did not properly validate source addresses in
the HTTP/3 QUIC module. A remote attacker could possibly use this issue to
bypass authorization checks or rate limiting. This issue only affected
Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-40460)
It was discovered that nginx contained a use-after-free vulnerability in
the ngx_http_ssl_module module when client certificate verification and
OCSP validation were enabled. A remote attacker could use this issue to
cause nginx to crash, resulting in a denial of service, or possibly modify
data in memory. (CVE-2026-40701)
It was discovered that nginx did not properly handle certain proxied
responses in the ngx_http_charset_module module. A
Red Hat
nginx: ngx_http_charset_module: information disclosure and denial of service
vendor_redhat·2026-05-13·CVSS 6.3
CVE-2026-42934 [MEDIUM] CWE-126 nginx: ngx_http_charset_module: information disclosure and denial of service
nginx: ngx_http_charset_module: information disclosure and denial of service
A flaw was found in the ngx_http_charset_module module of NGINX. When charset, source_charset, charset_map and proxy_pass with disabled buffering ("off") directives are configured, an unauthenticated attacker can send crafted requests and cause a heap-based buffer over-read in the worker process, resulting in a limited disclosure of memory or a denial of service by forcing the process to restart.
Statement: To exploit this vulnerability, the charset, source_charset, charset_map and proxy_pass directives must be configured with disabled buffering, limiting its exposure as this is not the default configuration. Also, configurations that do not recode a UTF-8 response through charset_map are not vulnerable. This is
F5
CVE-2026-42934: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module
vendor_f5·2026-05-13·CVSS 6.3
CVE-2026-42934 [MEDIUM] CWE-125 CVE-2026-42934: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module
CVE-2026-42934: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: NGINX Plus
F5 Advisory Articles: K000161028
F5 References: https://my.f5.com/manage/s/article/K000161028
GHSA
GHSA-6vmc-2wh4-77qp: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module
ghsa_unreviewed·2026-05-13
CVE-2026-42934 [MEDIUM] CWE-125 GHSA-6vmc-2wh4-77qp: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42934 nginx: ngx_http_charset_module: information disclosure and denial of service
bugzilla·2026-05-13·CVSS 6.3
CVE-2026-42934 [MEDIUM] CVE-2026-42934 nginx: ngx_http_charset_module: information disclosure and denial of service
CVE-2026-42934 nginx: ngx_http_charset_module: information disclosure and denial of service
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Hackernews
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
blogs_hackernews·2026-05-14·CVSS 9.2
CVE-2026-42945 [CRITICAL] 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years.
The vulnerability, discovered by depthfirst , is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to achieve remote code execution or cause a denial-of-service (DoS) with crafted requests. It has been codenamed NGINX Rift .
"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_modul
2026-05-13
Published