Out-of-bounds read in NGINX Plus and NGINX Open Source - CVE-2026-48142
Published: June 18, 2026
NGINX Plus
NGINX Open Source
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose limited memory contents or cause a worker process restart.
The vulnerability exists due to out-of-bounds read in ngx_http_charset_module when serving or proxying content through a location block configured with both source_charset utf-8 and a charset directive. A remote attacker can send crafted requests to disclose limited memory contents or cause a worker process restart.
This is a data plane issue only, and exploitation also depends on conditions beyond the attacker's control.