Junglewise Threat Intelligence

CVE-2026-42934: F5 NGINX heap buffer over-read in ngx_http_charset_module

CVE-2026-42934 · Severity: medium · CVSS 4.8 · Published 2026-05-13

Technologies: F5 Nginx Ingress Controller, F5 Nginx Plus, F5 Nginx Gateway Fabric, NGINX Open Source. Vendors: F5, NGINX.

Executive brief

NGINX Plus and NGINX Open Source, widely used web servers and load balancers, contain a vulnerability in their character set handling module. An unauthenticated attacker can send specific web requests that may cause the server to crash or leak small amounts of internal memory. This could lead to temporary service outages or the exposure of sensitive technical data.

Technical details

A heap buffer over-read vulnerability exists in the ngx_http_charset_module of NGINX. The flaw is triggered when the 'charset', 'source_charset', and 'charset_map' directives are used in conjunction with 'proxy_pass' while buffering is explicitly disabled ('proxy_buffering off'). An unauthenticated remote attacker can exploit this by sending crafted requests, though successful exploitation depends on conditions beyond the attacker's direct control. Impact includes a crash of the NGINX worker process (DoS) or limited disclosure of memory contents. Patches are available in NGINX Plus R32 P6, R36 P4, and NGINX Open Source 1.30.1/1.31.0.

Affected products

  • F5 NGINX Plus R32 before R32 P6, R36 before R36 P4
  • F5 NGINX Open Source 0.3.50 to 1.30.0
  • F5 NGINX Ingress Controller 4.0.0-4.0.1, 3.5.0-3.7.2, 5.0.0-5.4.2
  • F5 NGINX Gateway Fabric 1.3.0-1.6.2, 2.0.0-2.6.0

Timeline

  • 2026-05-13: advisory: Initial advisory published by F5
  • 2026-05-13: disclosed

References

Related threats