critical
CVE-2026-42533
nginx script-engine capture/map heap overflow (DoS; RCE where ASLR bypassable)
- Severity
- critical
- Affected product
- nginx
- Affected versions
- nginx ≥ 0.9.6, < 1.30.4
- Fixed in
- nginx 1.30.4 (stable) / 1.31.3 (mainline)
- Added to NewScan
- 2026-07-21
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints nginx from its response and reports this CVE when the detected version falls inside the affected range below.
Version-match only - actively triggering this overflow crashes the worker; never probe it. Needs a specific config (regex `map` output used in a string expr after an earlier capture), which isn't visible externally, so a banner match means "vulnerable build", not "confirmed exploitable".
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →