Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
The Hacker News
3 weeks ago

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

By info@thehackernews.com (The Hacker News)

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.