Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42934

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 4.8

Описание

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

A flaw was found in the ngx_http_charset_module module of NGINX. When charset, source_charset, charset_map and proxy_pass with disabled buffering ("off") directives are configured, an unauthenticated attacker can send crafted requests and cause a heap-based buffer over-read in the worker process, resulting in a limited disclosure of memory or a denial of service by forcing the process to restart.

Отчет

To exploit this vulnerability, the charset, source_charset, charset_map and proxy_pass directives must be configured with disabled buffering, limiting its exposure as this is not the default configuration. Also, configurations that do not recode a UTF-8 response through charset_map are not vulnerable. This issue allows an attacker to have limited control to disclose memory content from the worker process or cause a denial of service by forcing the process to restart, but it cannot cause a complete system denial of service. Due to these reasons, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, enable proxy buffering (the default configuration).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nginxOut of support scope
Red Hat Enterprise Linux 8nginx:1.24/nginxFix deferred
Red Hat Enterprise Linux 9nginxFix deferred
Red Hat Enterprise Linux 9nginx:1.24/nginxFix deferred
Red Hat Enterprise Linux 9nginx:1.26/nginxFix deferred
Red Hat Hardened ImagesnginxNot affected
Red Hat Lightspeed proxy 1insights-proxy/insights-proxy-container-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2477066nginx: ngx_http_charset_module: information disclosure and denial of service

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
nvd
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
msrc
3 месяца назад

NGINX ngx_http_charset_module vulnerability

CVSS3: 4.8
debian
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
github
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

4.8 Medium

CVSS3