Back

MEDIUM

NGINX ngx_http_charset_module vulnerability

Published Jun 17, 2026

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, avoid configuring NGINX with both `source_charset utf-8;` and an additional `charset` directive within the same location block in the `ngx_http_charset_module`. If these directives are not essential for your NGINX deployment, removing one or both will prevent the vulnerability from being exploited. After modifying the NGINX configuration, reload the NGINX service using `systemctl reload nginx`. This action may temporarily interrupt active connections.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner f5
Published Jun 17, 2026
Updated Jun 17, 2026
Reserved Jun 2, 2026

CISA Vulnrichment

Updated Jun 17, 2026

NVD

Status Analyzed
Modified Aug 11, 2026

Red Hat

Severity Moderate
Public date Jun 17, 2026
Bugzilla 2489858

ENISA EUVD

Assigner f5
Published Jun 17, 2026
Updated Jun 17, 2026

GitHub

No data