https://seclists.org/oss-sec/2026/q2/671: NGINX ngx_http_write_module buffer overflow (CVE-2026-9256)
Published May 22, 2026
·Updated
Affected Software
2 affected components
Nginx NGINX Open Source<1.31.1, <1.30.2
Nginx NGINX Plus
CVE-2026-9256 has been classified as a high-severity buffer overflow vulnerability.
To fix CVE-2026-9256, upgrade to NGINX versions 1.31.1 or 1.30.2 that contain the patched code.
CVE-2026-9256 can lead to remote code execution or crashes due to buffer overflow issues.
CVE-2026-9256 affects multiple versions of NGINX prior to the security updates in versions 1.31.1 and 1.30.2.
Yes, both NGINX Open Source and NGINX Plus are affected by the CVE-2026-9256 vulnerability.