CVE-2026-48142

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161585 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*

History

22 Jun 2026, 16:50

Type Values Removed Values Added
First Time F5 nginx Open Source
F5 nginx Ingress Controller
F5 nginx Instance Manager
F5 dos
F5 waf
F5 nginx Gateway Fabric
F5 nginx Plus
F5
CPE cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:*
References () https://my.f5.com/manage/s/article/K000161585 - () https://my.f5.com/manage/s/article/K000161585 - Vendor Advisory

17 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 15:16

Updated : 2026-06-22 16:50


NVD link : CVE-2026-48142

Mitre link : CVE-2026-48142

CVE.ORG link : CVE-2026-48142


JSON object : View

Products Affected

f5

  • dos
  • nginx_open_source
  • nginx_plus
  • nginx_ingress_controller
  • nginx_gateway_fabric
  • nginx_instance_manager
  • waf
CWE
CWE-125

Out-of-bounds Read