CVE-2026-42945
published 2026-05-13CVE-2026-42945: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed…
PriorityP191high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
61.47%
99.1th percentile
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | dos | — | — |
| f5 | dos | 4.3.0 – 4.7.0 | — |
| f5 | nginx_gateway_fabric | 1.3.0 – 1.6.2 | — |
| f5 | nginx_gateway_fabric | 2.0.0 – 2.5.1 | — |
| f5 | nginx_ingress_controller | 3.5.0 – 3.7.2 | — |
| f5 | nginx_ingress_controller | 4.0.0 – 4.0.1 | — |
| f5 | nginx_ingress_controller | 5.0.0 – 5.4.1 | — |
| f5 | nginx_instance_manager | 2.16.0 – 2.21.1 | — |
| f5 | nginx_open_source | >= 0.6.27 < 1.30.1 | 1.30.1 |
| f5 | nginx_open_source | 0.6.27 – 1.30.0 | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R32 < R32 P6 | R32 P6 |
| f5 | nginx_plus | >= R36 < R36 P4 | R36 P4 |
| f5 | nginx_plus | r32 – r36 | — |
| f5 | waf | 4.9.0 – 4.16.0 | — |
| f5 | waf | 5.1.0 – 5.8.0 | — |
| f5 | waf | 5.9.0 – 5.12.1 | — |
| insights-proxy | insights-proxy-container-rhel9 | — | — |
| nginx_1.24 | nginx | — | — |
| nginx_1.26 | nginx | — | — |
| ubuntu | nginx | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect repeated NGINX worker process crashes (crash loops), which indicate active exploitation attempts using CVE-2026-42945 to degrade availability. ↗
- →VulnCheck honeypot telemetry detected active exploitation attempts — monitor for scanning/probing activity consistent with automated vulnerability discovery against NGINX endpoints. ↗
- ·Vulnerability is only triggerable when the rewrite directive is followed by a rewrite, if, or set directive AND uses an unnamed PCRE capture ($1, $2) with a replacement string containing a question mark (?). Configurations not matching this pattern are not affected. ↗
- ·Remote code execution is only achievable on systems where ASLR is disabled; on ASLR-enabled systems (default on most Linux distributions), exploitation is limited to worker-process crash/DoS. ↗
- ·As a temporary mitigation if patching is not immediately possible, replace unnamed PCRE captures with named captures in all affected rewrite directives. ↗
- ·Affected NGINX versions span 0.6.27 through 1.30.0; versions 0.6.27–0.9.7 have no fix planned. The vulnerability was introduced in 2008. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.2CRITICAL
vendor_redhat9.2CRITICAL
vendor_ubuntu6.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-03·CVSS 6.3
CVE-2026-1642 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that the nginx ngx_mail_smtp_module module incorrectly
handled certain memory operations when doing SMTP authentication. This
could possibly result in sensitive information being sent to the
authentication server. (CVE-2025-53859)
It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server. (CVE-2026-1642)
It was discovered that the nginx ngx_mail_auth_http_module module
incorrectly handled certain requests. An attacker could possibly use this
issue to cause nginx to crash, resulting in a denial of service.
(CVE-2026-27651)
It was discovered that
Ubuntu
nginx vulnerability
vendor_ubuntu·2026-05-14
CVE-2026-42945 nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that the nginx ngx_http_rewrite_module component
incorrectly handled certain rewrite directives. A remote attacker could use
this issue to cause nginx to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
F5
CVE-2026-42945: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
vendor_f5·2026-05-13·CVSS 9.2
CVE-2026-42945 [CRITICAL] CWE-122 CVE-2026-42945: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
CVE-2026-42945: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software v
Red Hat
nginx: NGINX: Arbitrary Code Execution Vulnerability
vendor_redhat·2026-05-13·CVSS 9.2
CVE-2026-42945 [CRITICAL] CWE-131 nginx: NGINX: Arbitrary Code Execution Vulnerability
nginx: NGINX: Arbitrary Code Execution Vulnerability
A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests under specific rewrite configurations. This can lead to a heap buffer overflow in the NGINX worker process, which may result in arbitrary code execution if Address Space Layout Randomization (ASLR), a security technique to prevent exploitation, is disabled. Otherwise, this flaw causes a denial of service due to a restart of the NGINX worker process.
Statement: Critical: This flaw in NGINX's ngx_http_rewrite_module can lead to arbitrary code execution due to a heap buffer overflow if Address Space Layout Randomization (ASLR) is disabled, or a denial of service otherwise.
GHSA
GHSA-gcgv-v5gf-c543: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
ghsa_unreviewed·2026-05-13
CVE-2026-42945 [CRITICAL] CWE-122 GHSA-gcgv-v5gf-c543: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
VulnCheck
F5 nginx_open_source Heap-based Buffer Overflow
vulncheck·2026·CVSS 9.2
CVE-2026-42945 [CRITICAL] F5 nginx_open_source Heap-based Buffer Overflow
F5 nginx_open_source Heap-based Buffer Overflow
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) a
No detection rules found.
No public exploits indexed.
Hackernews
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
blogs_hackernews·2026-06-18
CVE-2026-42530 F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems.
The vulnerabilities are listed below -
CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is configured to use the HTTP/3 QUIC module to reopen a QPACK encoder stream by means of a specially crafted HTTP/3 session, and execute code on systems with Address Spac
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Checkpoint
18th May – Threat Intelligence Report
blogs_checkpoint·2026-05-18·CVSS 8.4
CVE-2026-44112 [HIGH] 18th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that customer data and core network infrastructure were not affected by the incident.
Cryptocurr
Hackernews
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
blogs_hackernews·2026-05-17·CVSS 9.2
CVE-2026-42945 [CRITICAL] NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck .
The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the vulnerability was introduced in 2008.
Successful exploitation of the flaw can permit an unauthenticated attacker to crash worker processes or execute r
Hackernews
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
blogs_hackernews·2026-05-14·CVSS 9.2
CVE-2026-42945 [CRITICAL] 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years.
The vulnerability, discovered by depthfirst , is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to achieve remote code execution or cause a denial-of-service (DoS) with crafted requests. It has been codenamed NGINX Rift .
"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_modul
Bugzilla
CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]
bugzilla·2026-05-14·CVSS 9.2
CVE-2026-42945 [CRITICAL] CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]
CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-094eb13bb1 (nginx-1.30.1-1.fc44, nginx-mod-brotli-1.0.0~rc-9.fc44, and 6 more) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-094eb13bb1
---
FEDORA-2026-fb53cb4d67 (nginx-1.30.1-1.fc43, nginx-mod-brotli-1.0.0~rc-9.fc43, and 5 more) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-fb53cb4d67
---
FEDORA-2026-38623b4fed (nginx-1.30.1-1.fc42, nginx-mod-brotli-1.0.0~
Bugzilla
CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability
bugzilla·2026-05-13·CVSS 9.2
CVE-2026-42945 [CRITICAL] CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability
CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software versions which have reached End of Techni
https://my.f5.com/manage/s/article/K000161019https://depthfirst.com/nginx-rifthttps://github.com/DepthFirstDisclosures/Nginx-Rifthttps://access.redhat.com/errata/RHSA-2026:17417https://access.redhat.com/errata/RHSA-2026:17751https://access.redhat.com/errata/RHSA-2026:17752https://access.redhat.com/errata/RHSA-2026:17753https://access.redhat.com/errata/RHSA-2026:17790https://access.redhat.com/errata/RHSA-2026:17791https://access.redhat.com/errata/RHSA-2026:17792https://access.redhat.com/errata/RHSA-2026:17793https://access.redhat.com/errata/RHSA-2026:17794https://access.redhat.com/errata/RHSA-2026:18029https://access.redhat.com/errata/RHSA-2026:18041https://access.redhat.com/errata/RHSA-2026:18063https://access.redhat.com/errata/RHSA-2026:19159https://access.redhat.com/errata/RHSA-2026:19371https://access.redhat.com/errata/RHSA-2026:19372https://access.redhat.com/errata/RHSA-2026:19374https://access.redhat.com/errata/RHSA-2026:20442https://access.redhat.com/errata/RHSA-2026:20444https://access.redhat.com/errata/RHSA-2026:21275https://access.redhat.com/errata/RHSA-2026:22382https://access.redhat.com/errata/RHSA-2026:22383https://access.redhat.com/errata/RHSA-2026:22388https://access.redhat.com/errata/RHSA-2026:22389https://access.redhat.com/errata/RHSA-2026:22390https://access.redhat.com/errata/RHSA-2026:22393https://access.redhat.com/errata/RHSA-2026:22394https://access.redhat.com/errata/RHSA-2026:22396https://access.redhat.com/security/cve/CVE-2026-42945https://bugzilla.redhat.com/show_bug.cgi?id=2477116https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json
2026-05-13
Published
Exploited in the wild