« Volver al listado

CVE-2026-42934

Estado: AnalizadaMedia (6.3)—

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42934",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42934",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-13T15:55:18.483975Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.2
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5",
          "modules": [
            "ngx_http_charset_module"
          ],
          "product": "NGINX Plus",
          "versions": [
            {
              "status": "unaffected",
              "version": "R37",
              "lessThan": "*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R36",
              "lessThan": "R36 P4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R32",
              "lessThan": "R32 P6",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "F5",
          "modules": [
            "ngx_http_charset_module"
          ],
          "product": "NGINX Open Source",
          "versions": [
            {
              "status": "unaffected",
              "version": "1.31.0",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.3.50",
              "lessThan": "1.30.1",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-13T16:16:49.910",
  "references": [
    {
      "url": "https://my.f5.com/manage/s/article/K000161028",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering (\"off\") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.\n\n\n\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    }
  ],
  "lastModified": "2026-06-18T14:07:22.880",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0772572C-26F9-4FA4-B9E6-BA40ED59F569",
              "versionEndIncluding": "4.7.0",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C45452BD-7A86-48E7-8E1D-1B340FF70B3B"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15B7F1FD-0C49-460F-9CB8-23DA730EC4BE",
              "versionEndIncluding": "1.6.2",
              "versionStartIncluding": "1.3.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A6AA23F-A7A1-43DE-AD67-0EB1249143A4",
              "versionEndIncluding": "2.6.0",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10D5B143-4C1E-4626-8B49-3EA7160E9256",
              "versionEndIncluding": "3.7.2",
              "versionStartIncluding": "3.5.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73A1CDBB-49F6-4AB6-AA67-542FD8017D6A",
              "versionEndIncluding": "4.0.1",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "607EEFA3-BE2A-4660-8C67-E6FC9799325F",
              "versionEndIncluding": "5.4.2",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBC31553-99DE-4155-A8E5-13A84FCCB610",
              "versionEndIncluding": "2.22.0",
              "versionStartIncluding": "2.16.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB2E27C7-2CF6-4EBD-8D5B-62AC1FAF2A82",
              "versionEndIncluding": "0.9.7",
              "versionStartIncluding": "0.3.50"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC94D0FA-F4AE-4178-AE9A-8CB645E3DF7C",
              "versionEndIncluding": "1.30.0",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B153576-468F-48C2-9BC8-922A938AB235",
              "versionEndIncluding": "r36",
              "versionStartIncluding": "r32"
            },
            {
              "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F365BA5A-42D7-4024-9143-06D4DEE31212",
              "versionEndIncluding": "4.16.0",
              "versionStartIncluding": "4.9.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D720985-9119-480E-929A-7D9D5C083628",
              "versionEndIncluding": "5.8.0",
              "versionStartIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE69C522-7FCB-4452-8E33-FCC72D36BF94",
              "versionEndIncluding": "5.12.1",
              "versionStartIncluding": "5.9.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}