CVE-2026-42934 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A heap buffer over-read vulnerability has been identified in the ngx_http_charset_module of NGINX Plus and NGINX Open Source. This issue arises when the charset, source_charset, charset_map, and proxy_pass directives with disabled buffering are configured. Under these conditions, unauthenticated attackers can send requests that exploit the vulnerability, leading to a heap buffer over-read in the NGINX worker process. This over-read can result in a limited disclosure of memory contents or cause a restart of the worker process.
Users can upgrade to NGINX Plus version 37.0.0 or NGINX Open Source versions 1.31.0 or 1.30.1 to address this vulnerability. For NGINX Instance Manager, versions 2.21.2 and later are recommended. NGINX App Protect WAF users should upgrade to version 5.9.0 or later. NGINX Ingress Controller users can upgrade to version 5.4.3 or later. For NGINX Gateway Fabric, versions 2.6.0 and 1.6.2 or later are recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161028 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 dos | >= 4.3.0, <= 4.7.0 4.8.0 |
CPE
Remediation
| |
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.6.0 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.4.2 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.16.0, <= 2.22.0 |
CPE
Remediation
| |
| f5 nginx open source | >= 0.3.50, <= 0.9.7 >= 1.0.0, <= 1.30.0 |
CPE
Remediation
| |
| f5 nginx plus | >= r32, <= r36 |
CPE
Remediation
| |
| f5 waf | >= 4.9.0, <= 4.16.0 >= 5.1.0, <= 5.8.0 >= 5.9.0, <= 5.12.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |