CybersecurityJuly 20, 2026· via The Hacker News

Critical NGINX flaw lets attackers crash servers remotely

Critical NGINX flaw lets attackers crash servers remotely

Image : The Hacker News

A critical flaw in NGINX could let attackers crash servers or execute malicious code with specially crafted HTTP requests, and patches are already available. Tracked as CVE-2026-42533, the vulnerability stems from a heap buffer overflow in worker processes, enabling remote, unauthenticated exploitation. F5 released fixes on July 15 for stable and mainline NGINX versions, as well as NGINX Plus, urging users to upgrade immediately.

How the flaw works and who’s affected

The issue arises when NGINX processes carefully crafted HTTP requests, triggering a heap-based buffer overflow in the worker process. This can crash or restart the worker, leading to service disruption. Exploitation requires no authentication, making it especially dangerous for exposed web servers. F5 patched the flaw in NGINX 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1, so any earlier build remains vulnerable.

No patch, no protection

F5’s rapid response—releasing fixes within weeks of discovery—highlights the severity. However, widespread adoption of unpatched versions could leave countless servers exposed to denial-of-service attacks or worse. Organizations running NGINX should prioritize updates, especially if their servers handle public-facing traffic. The timeline underscores how quickly attackers can weaponize newly disclosed flaws once details emerge.

Why it matters

This vulnerability isn’t just another theoretical risk—it’s an active threat to uptime and data integrity for web infrastructure. Server crashes and potential remote code execution can disrupt services and open doors to deeper breaches. For admins, the message is clear: patch now, audit configurations, and monitor for suspicious traffic. In an era of relentless attacks, even mature software like NGINX isn’t immune—vigilance and swift action are the best defenses.


Source: The Hacker News. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on The Hacker News →

← Back to home