PT-2026-40679 · F5+1 · Nginx Open Source+2

Published

2026-05-13

·

Updated

2026-05-15

·

CVE-2026-42934

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions NGINX Plus (affected versions not specified) NGINX Open Source (affected versions not specified)
Description A heap buffer over-read exists in the ngx http charset module module. This occurs when the charset, source charset, charset map, and proxy pass directives are configured, specifically with buffering disabled ("off"). Unauthenticated attackers can send requests that, under certain conditions, cause the NGINX worker process to read beyond the allocated heap buffer, potentially leading to a process restart or limited disclosure of memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

BIT-NGINX-2026-42934
BIT-NGINX-GATEWAY-2026-42934
CVE-2026-42934

Affected Products

Nginx Open Source
Nginx Plus
Nginx