What happened
A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · imbas007/CVE-2026-42533nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.RCEPython★ 35⑂ 9Code indexedUpdated 26 Aug 2026imbas0072026-07-27VerifiedCVE-Intel · suominen/CVE-2026-42533Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflowExploitShell★ 0⑂ 0Code indexedUpdated 25 Aug 2026Tags: cve, nginx, securitysuominen2026-07-21CandidateCVE-Intel · Leeyoonjoo/CVE-2026-42533ExploitPython★ 0⑂ 0Code indexedUpdated 17 Aug 2026Leeyoonjoo2026-08-12CandidateCVE-Intel · 0xCyberstan/CVE-2026-42533-POCCVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.RCEPython★ 1⑂ 0Code indexedUpdated 17 Aug 20260xCyberstan2026-08-05CandidateCVE-Intel · 0xCyberstan/CVE-2026-42533-Config-ScannerStatic config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).ExploitPython★ 30⑂ 5Code indexedUpdated 14 Aug 20260xCyberstan2026-07-04CandidateCVE-Intel · Daniyal48/ghostlock-vagrant-boxAn isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).LPE★ 1⑂ 0Updated 5 Aug 2026Daniyal482026-07-20CandidateCVE-Intel · jelasin/CVE-2026-42533ExploitC★ 0⑂ 1Code indexedUpdated 29 Jul 2026jelasin2026-07-27CandidateCVE-Intel · ChPratik/NGINX_2026_CVE_Bundle_CTI_ReportCovered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533Exploit★ 0⑂ 0Updated 28 Jul 2026ChPratik2026-07-28CandidateFranklinF25/cve-2026-42533★ 0FranklinF252026-08-29Verifiedgagaltotal/CVE-2026-42533-nginxCVE-2026-42533 Nginx★ 0gagaltotal2026-07-23Verifiedseguridadentrerios/CVE-2026-42533Vulnerabilidad en NGINX★ 1seguridadentrerios2026-07-22VerifiedSource timeline
Discovered through CVE-IntelView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.