important · Research — edge
New public exploit code turns nginx's capture-clobbering bug into pre-authentication code execution with ASLR enabled.
Affects
nginx Open Source and NGINX Plus web, reverse-proxy and stream servers on affected configurations.
The attack applies only when a configuration evaluates a regex capture before an attacker-influenced regex map variable in the same two-pass buffer; we do not know how common that pattern is.
Detail and 4 sources
Public modes now use the shorter-capture path to disclose heap addresses and the longer-capture path to replace a cleanup pointer, ending in system() when the corrupted connection closes.
Sources
Research15-year-old pre-auth nginx RCE across 13 call sites: two-pass capture clobbering (CVE-2026-42533) – cyberstanCode / PoCGitHub - 0xCyberstan/CVE-2026-42533-POC: CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE. · GitHubCode / PoCGitHub - 0xCyberstan/CVE-2026-42533-Config-Scanner: Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak). · GitHubVendornginx security advisories