F5 nginx security patch release for CVE-2026-42533
Security Patch Release
Summary
Hide ▲
Show ▼
F5 shipped security fixes for nginx and NGINX Plus to close CVE-2026-42533, a critical heap buffer overflow. Operators on nginx 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 are on the patched path; earlier builds need an upgrade. The release removes a remote unauthenticated request path that can crash the worker process and, in some configurations, may allow remote code execution.
Related Happenings
F5 security patch release for CVE-2026-42530
Security Patch Release
H score39
First: 18.06.2026 20:32
Last: 18.06.2026 20:32
Sources 1
About this happening:
F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
F5 security patch release for CVE-2026-42530
Security Patch ReleaseAbout this happening: F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
F5 NGINX out-of-band security updates (multiple vulnerabilities)
Security Patch Release
H score34
First: 18.06.2026 14:33
Last: 18.06.2026 14:33
Sources 1
About this happening:
F5 released out-of-band security updates for NGINX after finding multiple web server vulnerabilities, including two critical flaws that could enable remote code...
F5 NGINX out-of-band security updates (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: F5 released out-of-band security updates for NGINX after finding multiple web server vulnerabilities, including two critical flaws that could enable remote code...
LiteLLM endpoint-hardening patch release (CVE-2026-42271)
Security Patch Release
H score59
First: 09.06.2026 09:26
Last: 09.06.2026 09:26
Sources 1
About this happening:
BerriAI released LiteLLM 1.83.7, hardening access to the vulnerable MCP test endpoints that accepted full server configurations. The update now requires the PROXY_ADMIN*...
LiteLLM endpoint-hardening patch release (CVE-2026-42271)
Security Patch ReleaseAbout this happening: BerriAI released LiteLLM 1.83.7, hardening access to the vulnerable MCP test endpoints that accepted full server configurations. The update now requires the PROXY_ADMIN*...
Nginx security patch release for CVE-2026-49975
Security Patch Release
H score42
First: 03.06.2026 22:08
Last: 03.06.2026 22:08
Sources 1
About this happening:
Vendors released fixes for the HTTP/2 Bomb DoS issue, closing a path that could let a single client exhaust server memory within seconds. The patch set covers nginx 1.29...
Nginx security patch release for CVE-2026-49975
Security Patch ReleaseAbout this happening: Vendors released fixes for the HTTP/2 Bomb DoS issue, closing a path that could let a single client exhaust server memory within seconds. The patch set covers nginx 1.29...
Redis security patch release for CVE-2026-23479
Security Patch Release
H score24
First: 03.06.2026 16:47
Last: 03.06.2026 16:47
Sources 1
About this happening:
Redis released patched minor versions on May 5 to fix CVE-2026-23479, a use-after-free in blocking-client code that can lead to arbitrary OS command executio...
Redis security patch release for CVE-2026-23479
Security Patch ReleaseAbout this happening: Redis released patched minor versions on May 5 to fix CVE-2026-23479, a use-after-free in blocking-client code that can lead to arbitrary OS command executio...
Timeline
-
19.07.2026 23:42 2 articles · 19h ago
F5 nginx security patch release for CVE-2026-42533
Initial DisclosureF5 shipped patched nginx and NGINX Plus builds for CVE-2026-42533 and told operators on earlier versions to upgrade. The release closes a critical heap overflow that can be triggered through a specific regex-map request path.
Show sources
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — thehackernews.com — 19.07.2026 23:42
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — thehackernews.com — 19.07.2026 23:42