Is Your NGINX Server Truly Secure? F5 Warns of Critical Vulnerabilities That Could Lead to Remote Code Execution!
F5 has issued an official security advisory regarding several high-risk vulnerabilities affecting NGINX Plus and NGINX Open Source. According to security experts, successful exploitation of these vulnerabilities could result in memory corruption, denial of service (DoS), and, in certain cases, remote code execution (RCE).
The identified vulnerabilities affect widely deployed components, including NGINX Plus, NGINX Open Source, NGINX Ingress Controller, NGINX Gateway Fabric, NGINX App Protect WAF, and NGINX Instance Manager. Since these products are extensively used to power internet-facing web applications, API services, container platforms, and cloud environments, security professionals strongly recommend applying the available updates without delay.
Most Critical Vulnerability — CVE-2026-42533
The most severe vulnerability identified is CVE-2026-42533, which has been assigned a CVSS v3.1 score of 8.1 and a CVSS v4.0 score of 9.2.
This vulnerability is a Heap Buffer Overflow caused by a logic flaw in the way NGINX processes the map directive and regular expressions (regex).
By sending specially crafted HTTP requests, an attacker can corrupt the memory of an NGINX Worker Process.
As a temporary mitigation, F5 recommends using named regex captures instead of unnamed regex captures.
CVE-2026-60005 — Information Disclosure from Uninitialized Memory
The second vulnerability, CVE-2026-60005, has received a CVSS v3.1 score of 8.2 and a CVSS v4.0 score of 8.8.
The issue exists in the ngx_http_slice_module, which is not enabled by default and is only available in systems compiled with a specific build option.
F5 also recommends using named regex captures as a mitigation for this issue.
This is an extract. The publication continues at the source.
Read the original at the source: https://uzcert.uz/en/is-your-nginx-server-truly-secure-f5-warns-of-critical-vulnerabilities-that-could-lead-to-remote-code-execution/
Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- UZCERT — imported from official source
- Official source
- https://uzcert.uz/en/feed/ RSS
- Imported
- October 03, 2026 20:40
- Versions
- 1 recorded
- Identity
https://uzcert.uz/?p=39214