Dossier
CVE-2026-42533
Coverage of CVE-2026-42533 in the Nexus archive.
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 addressed a critical NGINX vulnerability (CVE-2026-42533) that allows remote, unauthenticated attackers to crash worker processes or potentially execute code via crafted HTTP requests. Fixes were released on July 15 in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1.