NGINX ngx_http_charset_module vulnerability
Published Jun 17, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.37%
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
-
Affected
- ≥ 1.13.10, < 1.31.2
- ≥ 1.30.0, < 1.30.3
-
Affected
- ≥ 37.0, < 37.0.2.1
- ≥ R36, < R36 P6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| F5 | NGINX Open Source | unknown | Affected
|
| F5 | NGINX Plus | unaffected | Affected
|
- ≥ 4.3.0 · ≤ 4.7.0
- 4.9.0
- ≥ 1.3.0 · ≤ 1.6.2
- ≥ 2.0.0 · ≤ 2.6.3
- ≥ 3.5.0 · ≤ 3.7.2
- ≥ 4.0.0 · ≤ 4.0.1
- ≥ 5.0.0 · ≤ 5.5.0
- ≥ 2.17.0 · ≤ 2.22.0
- ≥ 1.0.0 · ≤ 1.30.2
- ≥ 1.31.0 · ≤ 1.31.1
- ≥ 37.0.0.1 · < 37.0.2.1
- ≥ r33 · < r36
- r36
- r36
- r36
- r36
- r36
- r36
- ≥ 4.10.0 · ≤ 4.16.0
- ≥ 5.2.0 · ≤ 5.8.0
- ≥ 5.9.0 · ≤ 5.13.1
No data.
Red Hat Hardened Images
nginx-main-1.30.3-2.hum1
Fixed · RHSA-2026:27197
Red Hat Enterprise Linux 10
nginx
Fix deferred
Red Hat Enterprise Linux 8
nginx
Fix deferred
Red Hat Enterprise Linux 9
nginx
Fix deferred
Red Hat Enterprise Linux 9
nginx:1.24/nginx
Fix deferred
Red Hat Enterprise Linux 9
nginx:1.26/nginx
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | nginx-main-1.30.3-2.hum1 | Fixed | RHSA-2026:27197 |
| Red Hat Enterprise Linux 10 | nginx | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | nginx | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | nginx | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | nginx:1.24/nginx | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | nginx:1.26/nginx | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, avoid configuring NGINX with both `source_charset utf-8;` and an additional `charset` directive within the same location block in the `ngx_http_charset_module`. If these directives are not essential for your NGINX deployment, removing one or both will prevent the vulnerability from being exploited. After modifying the NGINX configuration, reload the NGINX service using `systemctl reload nginx`. This action may temporarily interrupt active connections.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-48142 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2489858 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37719 Advisory
- https://my.f5.com/manage/s/article/K000161585 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-48142
- https://www.cve.org/CVERecord?id=CVE-2026-48142
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-48142 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2489858 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37719 | Advisory | |
| https://my.f5.com/manage/s/article/K000161585 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-48142 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-48142 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data