PT-2026-50442 · F5+4 · Nginx Plus+5

CVE-2026-48142

·

Published

2026-06-17

·

Updated

2026-08-11

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NGINX Plus (affected versions not specified) NGINX Open Source (affected versions not specified)
Description A heap buffer over-read exists in the ngx http charset module module. This occurs when content is served or proxied through a location block configured with both source charset utf-8; and a charset directive (such as charset koi8-r;). Remote, unauthenticated attackers can send requests that, under specific conditions, cause the NGINX worker process to experience a heap buffer over-read, which is a memory error where the system reads data beyond the end of the intended buffer. This can lead to a restart of the process or limited disclosure of memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91176
BDU:2026-08934
BIT-NGINX-2026-48142
BIT-NGINX-GATEWAY-2026-48142
BIT-NGINX-GATEWAY-FABRIC-2026-48142
CVE-2026-48142
ECHO-B826-4D3A-4F4E
OESA-2026-2798
OESA-2026-2799
OESA-2026-2800
OESA-2026-2801
OPENSUSE-SU-2026:11066-1
OPENSUSE-SU-2026:21439-1
RHSA-2026:27197
SUSE-SU-2026:22943-1
SUSE-SU-2026:22951-1
SUSE-SU-2026:3329-1
SUSE-SU-2026:3448-1
USN-8458-1

Affected Products

Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Ubuntu