Impact
The vulnerability arises when a map directive uses regex matching and the resulting capture variables are referenced before the map output variable is retrieved, causing a heap buffer overflow in the NGINX worker process. This corrupts memory, leads to an immediate restart, and thereby produces a denial‑of‑service. If Address Space Layout Randomization is disabled or can be bypassed, the same flaw allows an attacker to inject code and achieve arbitrary execution. The issue exists only in the data plane; no control‑plane interfaces are exposed.
Affected Systems
Both F5 NGINX Open Source and NGINX Plus are affected. No specific version information is listed in the advisory; the vulnerability applies to all unpatched releases of these products that implement the described map directive behavior.
Risk and Exploitability
With a CVSS score of 9.2 the flaw is considered critical. The EPSS score of 3% indicates that, while exploitation is theoretically possible, the probability of real‑world attacks remains low at this time. The vulnerability is not included in the CISA KEV catalog. Attackers would need only to send a crafted HTTP request, do not require authentication, and would benefit from ASLR being disabled to achieve code execution. The failure causes a service restart, which may temporarily interrupt traffic but does not expose configuration or database secrets.
OpenCVE Enrichment
Ubuntu USN