Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests CVE202642533 was patched on July 15 in nginx 1304 stable and 1313 mainline and in NGINX Plus 37031 anyone on an earlier build should upgrade Triggering it can crash or restart the worker causing a denial of