CVE-2026-42934Disclosure(f5 / dos)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 dos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dos
  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-15); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
dosnginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_pluswaf

1 version affected across 7 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-15: 3Mentions · 2026-05-16: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-16: 105-1505-16
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-153
Disclosure2Patch1
2026-05-161
Disclosure1
Full discourse4 posts
  • Matthew Rosenquist@Matt_Rosenquist
    Disclosure

    More chained vulns are being discovered because of AI tools NGINX Rift is the latest Remote Code Execution (RCE), that combines 4 vulns CVE-2026-42945 Critical (9.2) CVE-2026-42946 High (8.3) CVE-2026-40701 Medium (6.3) CVE-2026-42934 Medium (6.3) https://api.cyfluencer.com/s/nginx-rift-chain-remote-code-execution-rce-discovered-leveraging-18-year-old-vulnerabilities-1cb958a3-27380/1

    Post summary

    The post announces the discovery of the NGINX Rift RCE chain, detailing four CVEs with their severity scores and directing readers to an article for further information.

    00010123
    1.2K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-42934 | F5 NGINX Plus/NGINX Open Source ngx_http_charset_module out-of-bounds (K000161028 / Nessus ID 314992) https://ift.tt/AxJFuv4 A vulnerability described as problematic has been identified in F5 NGINX Plus and NGINX Open Source. Affected by this vulnerability is …

    Post summary

    A new out‑of‑bounds vulnerability (CVE‑2026‑42934) affecting the ngx_http_charset_module in F5 NGINX Plus and Open Source NGINX has been identified, but no PoC, exploit, patch, or active exploitation details are provided.

    0000044
    974 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-42934 | F5 NGINX Plus/NGINX Open Source ngx_http_charset_module out-of-bounds (K000161028 / WID-SEC-2026-1527) https://ift.tt/AxJFuv4 A vulnerability described as problematic has been identified in F5 NGINX Plus and NGINX Open Source. Affected by this vulnerability is…

    Post summary

    The text announces the identification of a CVE-2026-42934 out‑of‑bounds vulnerability in F5 NGINX Plus and NGINX Open Source’s ngx_http_charset_module.

    0000052
    974 followersView on X
  • Vũ Trụ Số@vutruso
    Patch

    Nginx 1.31.0 Security Update - 6 CVEs Fixed CVE-2026-42945 - Heap buffer overflow in ngx_http_rewrite_module (potential code execution) CVE-2026-42926 - HTTP/2 request injection via proxy_set_body CVE-2026-42946 CVE-2026-42934 CVE-2026-40460 CVE-2026-40701 https://t.co/eRNItKkZIM

    Post summary

    Nginx 1.31.0 has released a security update fixing six CVEs, including a heap buffer overflow and HTTP/2 injection vulnerability, with no evidence of active exploitation or PoC dissemination.

    0000085
    35 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appf5dos-nginx-
Appf5dos4.8.0nginx-
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5waf-nginx-

Explore more