宝塔用户_xuncki 发表于 2026-7-21 16:43:30

nginx1.30.0-1.30.3 1.31.2you




NGINX 在处理包含变量和正则捕获的字符串表达式时,会使用脚本引擎在请求阶段动态拼接结果。 CVE-2026-42533 是 NGINX 在处理 map 指令正则匹配和字符串变量拼接时产生的堆缓冲区溢出漏洞。 在特定配置条件下,远程未认证攻击者可通过构造 HTTP 请求触发该漏洞,实现任意代码执行。



ProductBranchVersions known to be vulnerable1Fixes introduced inSeverity/CVSS score2Vulnerable component or feature
NGINX Plus37.x37.0.0.1 - 37.0.2.137.0.3.1High/8.1 (CVSS v3.1)
Critical/9.2 (CVSS v4.0)The map directive with regex matching
RxR33 - R36R36 P7
NGINX Open Source1.x1.31.2
1.30.0 - 1.30.31.31.3
1.30.4High/8.1 (CVSS v3.1)
Critical/9.2 (CVSS v4.0)The map directive with regex matching

页: [1]
查看完整版本: nginx1.30.0-1.30.3 1.31.2you