PT-2026-40679 · F5 · Nginx Open Source+1

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-42934

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
NGINX Plus and NGINX Open Source have a vulnerability in the ngx http charset module module. When charset, source charset, and charset map and proxy pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.
 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-42934

Affected Products

Nginx Open Source
Nginx Plus