F5 has released patches for a critical security issue in nginx, tracked as CVE-2026-42533. The flaw affects the web server’s handling of a regex map condition and can be exploited by a remote attacker without authentication.

According to the available details, the bug can be triggered with specially formed HTTP requests. Successful exploitation causes a heap buffer overflow inside the nginx worker process, which can lead to worker crashes and service disruption.

The impact may go beyond denial of service. F5 said the vulnerability could also open the door to remote code execution in certain configurations, making the issue especially serious for exposed or high-traffic deployments.

The fix is now available, and the update addresses the underlying memory handling problem. Organizations running nginx should review their environments and apply the patched version promptly, particularly if their setup matches the conditions linked to the elevated RCE risk.