Executive brief
NGINX Plus and NGINX Open Source, widely used web server and proxy software, contain a vulnerability in their character set handling module. Under specific configuration conditions, an unauthenticated attacker can send malicious requests that cause the server to crash or leak small amounts of internal memory. This could lead to temporary service outages or the exposure of sensitive technical data.
Technical details
A heap buffer over-read vulnerability exists in the ngx_http_charset_module of NGINX. The flaw is triggered when a location block is configured with both 'source_charset utf-8;' and a 'charset' directive (e.g., 'charset koi8-r;'). A remote, unauthenticated attacker can exploit this by sending specific requests that, in conjunction with certain environmental conditions, cause the NGINX worker process to read beyond allocated buffer boundaries. This results in either limited disclosure of memory contents or a worker process crash (DoS). The vulnerability is tracked as CWE-125. Patches are available in NGINX Open Source 1.31.2, 1.30.3, and NGINX Plus R36 P6 and 37.0.2.1.
Affected products
- F5 NGINX Open Source 1.13.10 to 1.31.1, 1.30.0 to 1.30.2
- F5 NGINX Plus R36 P0 to R36 P5, 37.0 to 37.0.2.0
Timeline
- 2026-06-17: advisory: Initial disclosure by F5 Networks
- 2026-06-17: disclosed