CVE-2026-42934

Published: May 15, 2026Last modified: May 19, 2026

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Severity score breakdown

ParameterValue
Base score4.8
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnginxFixed (1.22.1-r5)
25 LTSnginxFixed (1.28.3-r2)
StreamnginxFixed (1.30.1-r0)

References

ON THIS PAGE