August 7, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-42934NVD

Vulnerability Summary

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.



 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Severity Level
MEDIUM(4.8)
Published Date
May 13, 2026
Last Modified
Jun 8, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.72%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityLow