CVE-2026-48142: NGINX ngx_http_charset_module vulnerability
NGINX ngxhttpcharsetmodule vulnerability
Other sources
NGINX Plus and NGINX Open Source have a vulnerability in the ngxhttpcharsetmodule module. When content is served or proxied through a location block with both sourcecharset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.28.3-6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48142?
The severity of CVE-2026-48142 is medium with a CVSS score of 6.3.
What systems are affected by CVE-2026-48142?
CVE-2026-48142 affects NGINX Plus and NGINX Open Source versions.
How do I fix CVE-2026-48142?
To fix CVE-2026-48142, you should upgrade to the latest patched version of NGINX.
What type of attack does CVE-2026-48142 facilitate?
CVE-2026-48142 allows remote, unauthenticated attackers to exploit charset configurations in NGINX.
When was CVE-2026-48142 published?
CVE-2026-48142 was published on June 17, 2026.