SECURITY·중요도 9·2026. 07. 19.·The Hacker News
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
── KO ──────────────────
NGINX의 심각한 취약점으로 원격 코드 실행이 가능하다.
F5는 원격 인증되지 않은 공격자가 crafted HTTP 요청으로 nginx 작업 프로세스에서 힙 버퍼 오버플로를 유발할 수 있는 취약점을 수정했다. CVE-2026-42533은 7월 15일 nginx 1.30.4와 1.31.3 및 NGINX Plus 37.0.3.1에서 패치되었으며, 이전 빌드를 사용 중인 사용자는 업그레이드해야 한다.
── EN ──────────────────
A critical NGINX vulnerability allows for potential remote code execution.
F5 has released fixes for a critical vulnerability in NGINX that allows unauthenticated remote attackers to trigger a heap buffer overflow in the worker process via crafted HTTP requests. The vulnerability, identified as CVE-2026-42533, was patched on July 15 in NGINX versions 1.30.4, 1.31.3, and NGINX Plus 37.0.3.1. Users on earlier builds are advised to upgrade.