Back to overview

CVE-2026-48142

MEDIUM
4.8
CVSS 3.1
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metadata

CVE ID
CVE-2026-48142
State
PUBLISHED
Assigner
f5
Reserved
2026-06-02 21:45 UTC
Published
2026-06-17 14:04 UTC
Last updated
2026-06-17 15:42 UTC
Primary CWE
CWE-125
CWE-125 Out-of-bounds Read
Vendor / Product
F5 / NGINX Open Source
Sources
cve.org  ·  NVD

Severity & Metrics

4.8 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (2)
VendorProductPlatformVersions
F5 NGINX Open Source 1.13.10 < 1.31.2, 1.30.0 < 1.30.3
F5 NGINX Plus 37.0 < 37.0.2.1, R36 < R36 P6
Weakness (CWE)
CWESourceDescription
CWE-125 cna CWE-125 Out-of-bounds Read
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
4.8 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Back to overview