Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Nginx Vulnerability Demands Immediate Patching

Critical Nginx Vulnerability Demands Immediate Patching

Posted on May 23, 2026 By CWS

A significant security flaw has been identified in Nginx, one of the most prevalent web servers globally, urging administrators to urgently apply patches. Known as CVE-2026-9256 or ‘nginx-poolslip,’ this vulnerability impacts both NGINX Plus and NGINX Open Source, potentially allowing remote attackers to execute malicious actions over plain HTTP.

Understanding the Nginx-poolslip Vulnerability

The issue is located in the ngx_http_rewrite_module, which is also responsible for the previous ‘NGINX Rift’ flaw (CVE-2026-42945). As per an advisory from F5, this vulnerability occurs when a rewrite directive employs a regex pattern with overlapping PCRE capture groups, such as ^/((.*))$, combined with a replacement string like $1$2 in settings for redirects or arguments.

Attackers can exploit this by crafting requests that cause a heap buffer overflow in the NGINX worker process. Each request uses a dedicated memory pool, which NGINX clears upon completion. If an attacker manipulates the linked list of cleanup handlers in the pool, it may lead to a hijack of control flow.

Exploitation and Risks

Unlike the Rift bug, which was due to a buffer-size miscalculation, poolslip involves a controlled pointer slip across linked structures in the same pool. The previous patch did not address the memory pool’s vulnerability, allowing poolslip to affect even updated software versions.

Exploitation of this flaw can cause the worker process to crash and restart, resulting in a denial of service. More critically, it could lead to code execution if Address Space Layout Randomization (ASLR) is disabled or bypassed. F5 emphasizes that this is strictly a data-plane issue, with no exposure to the control plane, carrying a CVSS rating of High/8.1 to Critical/9.2.

Versions Affected and Recommended Actions

The flaw affects NGINX Open Source versions from 0.1.17 to 1.30.1 and 1.31.0, urging upgrades to 1.30.2 or 1.31.1. NGINX Plus users should update to R36 P5 or R32 P7, while 37.x users should move to R37.0.1.1. Related products like NGINX Instance Manager and F5 WAF for NGINX also inherit this vulnerability and should be updated accordingly.

Should immediate patching be impractical, F5 advises modifying affected rewrite directives by replacing unnamed captures with named ones. This involves using (?…) instead of $1 and $2, with references by name in replacement strings.

Call to Action

Discovered by Mufeed VH from Winfunc Research, Nebula Security, and Vexera AI, with proof-of-concept exploits already in circulation, organizations are urged to patch their systems without delay to mitigate this risk.

Stay informed by following us on Google News, LinkedIn, and X for more updates.

Cyber Security News Tags:code execution, CVE-2026-9256, Cybersecurity, denial of service, F5 advisory, heap buffer overflow, NGINX, NGINX Open Source, NGINX Plus, security patch, Vulnerability, web server security

Post navigation

Previous Post: New Vulnerability ‘Underminr’ Masks Malicious Networks
Next Post: AI Model Uncovers 10,000 Critical Software Flaws

Related Posts

First-ever AI-powered ‘MalTerminal’ Malware uses OpenAI GPT-4 to Generate Ransomware Code First-ever AI-powered ‘MalTerminal’ Malware uses OpenAI GPT-4 to Generate Ransomware Code Cyber Security News
SecurityMetrics Wins “Data Leak Detection Solution of the Year” at the 2025 CyberSecurity Breakthrough Awards SecurityMetrics Wins “Data Leak Detection Solution of the Year” at the 2025 CyberSecurity Breakthrough Awards Cyber Security News
Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability Cyber Security News
DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment Cyber Security News
PoC Exploit Released for Fortinet 0-Day Vulnerability that Allows Remote Code Execution PoC Exploit Released for Fortinet 0-Day Vulnerability that Allows Remote Code Execution Cyber Security News
FancyBear Security Breach Uncovers NATO Espionage Efforts FancyBear Security Breach Uncovers NATO Espionage Efforts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark