CVE-2026-42533
CriticalAdvisory
Published 15 Jul 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.2
- base score, highest
- EPSS
- 0.045
- 91st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 119
- of 17,781 indexed, latest versions
- Container images
- 119
- deployed by those charts
- Fix available
- 6 of 6
- affected packages
NGINX Map directive and Regex matching vulnerability
Carried by container images the latest versions of 119 of 17,781 indexed charts deploy, on 119 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nginxdeb | 1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+35 more | 1.18.0-6ubuntu14.20, 1.24.0-2ubuntu7.17, 1.26.3-3+deb13u8 | 88 |
| nginxapk | 1.26.2-r4, 1.26.3-r0, 1.28.0-r3, 1.28.1-r1+4 more | 1.26.3-r2, 1.28.3-r6 | 14 |
| nginxbitnami | 1.25.5-0, 1.27.1-2, 1.28.0-0, 1.31.3-0 | 1.30.4 | 4 |
| nginx-mainlineapk | 1.27.4-r0, 1.27.4-r2, 1.29.8-r1 | 1.31.3-r0 | 3 |
| NGINX Open Sourcebitnami | 1.25.5-0 | 1.30.4 | 1 |
| nginxrpm | 1:1.20.1-13.el9, 1:1.22.1-5.module+el9.3.0.z+20438+032561a0, 1:1.22.1-8.module+el9.5.0+22953+b175c265.1, 1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3+3 more | 1.21.5-150600.10.27.1, 2:1.20.1-28.el9_8.6 | 10 |
- OSV records
- ALPINE-CVE-2026-42533BIT-nginx-2026-42533CGA-3cc9-j23w-933vDEBIAN-CVE-2026-42533RHSA-2026:66542UBUNTU-CVE-2026-42533SUSE-SU-2026:3469-1
- Also known as
- BIT-nginx-gateway-2026-42533, CGA-x99p-pq5w-pxj6, USN-8563-1, USN-8563-2, USN-8563-3, USN-8563-4
Charts affected
119 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| synapse-adminschoenwald | 1.0.1 | 1 of 1See more | 1,802 |
| tabixsinextraVerified publisher | 0.2.2 | 1 of 1See more | 1,249 |
| cost-analyzersoftonic | 2.5.5 | 1 of 6See more | 7,901 |
| substra-frontendsubstraVerified publisher | 1.2.3 | 1 of 1See more | 3,032 |
| netforge-besvtechVerified publisher | 0.0.2 | 1 of 3See more | 4,674 |
| tarkatarkaOfficialVerified publisher | 0.4.1 | 1 of 4See more | 1,556 |
| super-mariotechpreta | 0.1.1 | 1 of 1See more | 6,297 |
| mrasiftech-thinker | 1.0.4 | 1 of 1See more | 2,043 |
| tensor_apptensor-app | 0.2.2 | 2 of 3See more | 17,461 |
| chatqnatest-opea | 1.0.0 | 1 of 11See more | 39,090 |
| codegentest-opea | 1.0.0 | 1 of 5See more | 28,814 |
| codetranstest-opea | 1.0.0 | 1 of 5See more | 28,385 |
| docsumtest-opea | 1.0.0 | 1 of 5See more | 28,858 |
| orchestra-login-portaltremolo | 2.3.97 | 1 of 1See more | 2,956 |
| opencloudunxwaresVerified publisher | 0.2.3 | 6 of 13See more | 45,239 |
| sirenwateim | 1.0.2 | 1 of 1See more | 5,984 |
| webhookiewebhookie | 0.1.2 | 1 of 1See more | 14,364 |
| webhookie-allwebhookie | 0.1.2 | 1 of 3See more | 28,605 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,673 |
Container images carrying it
119 by charts deploying them
A fixed version is listed for 6 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 287ff321f9e3 | nginx | no fix listed | 4 |
| library/ | a484819eb602 | nginx | no fix listed | 3 |
| ghcr.io/ | 6a5594b7b32c | nginx | no fix listed | 3 |
| hookiesolutions/ | 0629694246ba | nginx | no fix listed | 2 |
| library/ | 98f8ec75657d | nginx | no fix listed | 2 |
| moreillon/ | c9f85db3baa5 | nginx | no fix listed | 2 |
| moreillon/ | b067dbbbb6af | nginx | no fix listed | 2 |
| opencloudeu/ | 1691ad6612a3 | nginx | no fix listed | 2 |
| opencloudeu/ | 27cb9b952f0d | nginx | no fix listed | 2 |
| opencloudeu/ | 5b176baa3694 | nginx | no fix listed | 2 |
| opencloudeu/ | 6e8b2df6c5a4 | nginx | no fix listed | 2 |
| opencloudeu/ | 82f888a34440 | nginx | no fix listed | 2 |
| opencloudeu/ | e0ac35a9576e | nginx | no fix listed | 2 |
| ghcr.io/ | 3db8145349a3 | nginx | no fix listed | 2 |
| allegroai/ | 713ae38f7daf | nginx | no fix listed | 1 |
| avzini/ | f40b30210ed0 | nginx | no fix listed | 1 |
| awesometechnologies/ | a1c1f4662875 | nginx | 1.28.3-r6 | 1 |
| bitnamilegacy/ | 934d1acd5ca8 | nginx | 1.30.4 | 1 |
| bitnamilegacy/ | eaf9066e86f6 | nginx | 1.30.4 | 1 |
| ckulka/ | 434bdd162247 | nginx | no fix listed | 1 |
| codetogether/ | 4348c8a38752 | nginx | 2:1.20.1-28.el9_8.6 | 1 |
| conductoross/ | 9fba127693e6 | nginx | 1.26.3-3+deb13u8 | 1 |
| countly/ | e3c238248f99 | nginx | no fix listed | 1 |
| dachichang/ | 7ccac90a935e | nginx | no fix listed | 1 |
| dannielkil/ | 937993927694 | nginx | no fix listed | 1 |
| datamate/ | 2dd66b722464 | nginx | no fix listed | 1 |
| emqx/ | e33e9816f147 | nginx | no fix listed | 1 |
| extrim/ | 9cb7eb5598b6 | nginx | 1.26.3-r2 | 1 |
| felipecs8/ | 29e06c9c6385 | nginx | no fix listed | 1 |
| fnzv/ | b3079b95c336 | nginx | 1.18.0-6ubuntu14.20 | 1 |
| galaxy/ | 8e577a626dfd | nginx | no fix listed | 1 |
| hazegoodlife/ | 50f02d2d5d4d | nginx | no fix listed | 1 |
| hazegoodlife/ | 8d4c63169e14 | nginx | no fix listed | 1 |
| heartexlabs/ | aa461572e8f9 | nginx | 1.28.3-r6 | 1 |
| hecrom/ | bb0372939c19 | nginx | no fix listed | 1 |
| intel/ | 1a89327e499b | nginx | no fix listed | 1 |
| jeboehm/ | 9da13edf5aa8 | nginx | 1.28.3-r6 | 1 |
| kuzwolka/ | 1ad759b961b1 | nginx | no fix listed | 1 |
| kuzwolka/ | 3e8880fbbb96 | nginx | no fix listed | 1 |
| kuzwolka/ | 4a7707410bf1 | nginx | no fix listed | 1 |
| kuzwolka/ | 84a9d9766345 | nginx | no fix listed | 1 |
| lancachenet/ | 37f28b362c93 | nginx | no fix listed | 1 |
| langflowai/ | 54f67f1961fe | nginx | no fix listed | 1 |
| library/ | 09369da6b103 | nginx | no fix listed | 1 |
| library/ | 6784fb0834aa | nginx | no fix listed | 1 |
| library/ | 67f9a4f10d14 | nginx | no fix listed | 1 |
| library/ | 9ff236ed47fe | nginx | no fix listed | 1 |
| library/ | a8b39bd9cf0f | nginx | 1.28.3-r6 | 1 |
| library/ | fb197595ebe7 | nginx | no fix listed | 1 |
| linuxserver/ | 2ebf97852661 | nginx | 1.28.3-r6 | 1 |