CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8563-4: nginx regression

unknownpublic exploitCVE-2026-42533CVE-2026-56434CVE-2026-60005
USN-8563-3 fixed a vulnerability in nginx. The fix introduced a regression in certain environments. This update reverts the fix for CVE-2026-42533 pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434) It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005)

CSIRTS triage

What
Regression introduced by CVE-2026-42533 fix requiring revert pending further investigation; original vulnerabilities include incorrect regex map handling and use-after-free in SSI module.
Who is affected
nginx installations with map directives using regex capture variables, or SSI with proxy_pass and buffering disabled.
Urgency
Medium; regression fix reverts protection against DoS and RCE but vulnerability details require investigation.
Action
Apply USN-8563-4 to revert problematic fix and monitor for corrected patch addressing CVE-2026-42533 properly.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch nginx

Get an email when a new nginx advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-19
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8563-4

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-42533coverage & exploitation statusNVD · CVE.org
CVE-2026-56434coverage & exploitation statusNVD · CVE.org
CVE-2026-60005coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices