CVE-2026-42533/CVE-2026-60005/CVE-2026-56434
Author: HanadaLeeCreated Jul 16, 2026Updated Jul 31, 2026
This vulnerability has a wide scope of impact and is severe. It requires patching as soon as possible. @zhuizhuhaomeng
https://nginx.org/en/security_advisories.html
Buffer overflow when using map and regex Severity: major Advisory CVE-2026-42533 Not vulnerable: 1.31.3+ Vulnerable: 0.9.6-1.31.2
Memory disclosure when using ngx_http_slice_module Severity: medium Advisory CVE-2026-60005 Not vulnerable: 1.31.3+ Vulnerable: 1.15.8-1.31.2
Use-after-free when using mgx_http_ssi_module Severity: medium Advisory CVE-2026-56434 Not vulnerable: 1.31.3+ Vulnerable: 0.8.11-1.31.2
Source: openresty/openresty