CVE-2026-42946

NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


We have discovered 2,703,794 live websites that are affected by CVE-2026-42946.

Run a Free Instant Scan




Affected Software

Product  Nginx
Category Web Servers
Vulnerable Domains2,703,794 live websites (92% of Nginx install base)
Vulnerable Versions
  • from 0.8.42 through 1.30.1
Vulnerable Versions Count231 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-789 Memory Allocation with Excessive Size Value



Details

  • Published - May 13, 2026
  • Updated - May 13, 2026

Credits

  • F5 acknowledges Zhenpeng (Leo) Lin of depthfirst for bringing this issue to our attention and following the highest standards of coordinated disclosure. (finder)

Website Distribution by Country

Number of websites using CVE-2026-42946
United States769,353 websites



Russia494,070 websites
British Virgin Islands279,306 websites
Germany155,309 websites
China141,961 websites
GB104,480 websites
France85,718 websites
Brazil61,153 websites
Netherlands47,373 websites
Italy47,286 websites

Website Distribution by TLD

Number of websites using CVE-2026-42946
.com1,081,445 websites
.ru473,892 websites
.org111,273 websites
.net99,218 websites
.de61,884 websites
.cn61,705 websites
.co.uk58,974 websites
.com.br55,066 websites
.it41,120 websites
.cz29,382 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-42946

Top websites that are affected by CVE-2026-42946. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
*****.org United States***
******.com British Virgin Islands***
****.*********.com British Virgin Islands***
******.de Germany***
****.******.org United States***
**.*****.com United States***
********.**************.com United States***
***.**.**.com China***
*******.com United States***
See full domain list

FAQ

CVE-2026-42946 is Memory Allocation with Excessive Size Value in Nginx
A total of 2,703,794 websites have been identified as vulnerable to CVE-2026-42946, based on global website indexing conducted by WebTechSurvey.
The Nginx is affected by the CVE-2026-42946 vulnerability.
Nginx versions up to 1.30.1 are vulnerable to CVE-2026-42946.
CVE-2026-42946 is resolved in version 1.30.1 of Nginx.