CVE-2026-42946
published 2026-05-13CVE-2026-42946: A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data…
PriorityP350high7.4CVSS 3.1
AVNACHPRNUINSUCHINAH
EPSS
0.93%
57.0th percentile
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | dos | — | — |
| f5 | nginx_app_protect_dos | 4.3.0 – 4.7.0 | — |
| f5 | nginx_app_protect_waf | 4.9.0 – 4.16.0 | — |
| f5 | nginx_app_protect_waf | 5.1.0 – 5.8.0 | — |
| f5 | nginx_gateway_fabric | 1.3.0 – 1.6.2 | — |
| f5 | nginx_gateway_fabric | 2.0.0 – 2.6.0 | — |
| f5 | nginx_ingress_controller | 3.5.0 – 3.7.2 | — |
| f5 | nginx_ingress_controller | 4.0.0 – 4.0.1 | — |
| f5 | nginx_ingress_controller | 5.0.0 – 5.4.2 | — |
| f5 | nginx_instance_manager | 2.16.0 – 2.22.0 | — |
| f5 | nginx_open_source | >= 0.8.42 < 1.30.1 | 1.30.1 |
| f5 | nginx_open_source | 0.8.42 – 0.9.7 | — |
| f5 | nginx_open_source | 1.0.0 – 1.30.0 | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R32 < R32 P6 | R32 P6 |
| f5 | nginx_plus | >= R36 < R36 P4 | R36 P4 |
| f5 | nginx_plus | r32 – r36 | — |
| f5 | waf | 5.9.0 – 5.12.1 | — |
| insights-proxy | insights-proxy-container-rhel9 | — | — |
| nginx_1.24 | nginx | — | — |
| nginx_1.26 | nginx | — | — |
| ubuntu | nginx | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv4.08.3HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.3HIGH
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-03·CVSS 6.3
CVE-2026-1642 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that the nginx ngx_mail_smtp_module module incorrectly
handled certain memory operations when doing SMTP authentication. This
could possibly result in sensitive information being sent to the
authentication server. (CVE-2025-53859)
It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server. (CVE-2026-1642)
It was discovered that the nginx ngx_mail_auth_http_module module
incorrectly handled certain requests. An attacker could possibly use this
issue to cause nginx to crash, resulting in a denial of service.
(CVE-2026-27651)
It was discovered that
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 6.9
CVE-2026-9256 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx did not properly validate source addresses in
the HTTP/3 QUIC module. A remote attacker could possibly use this issue to
bypass authorization checks or rate limiting. This issue only affected
Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-40460)
It was discovered that nginx contained a use-after-free vulnerability in
the ngx_http_ssl_module module when client certificate verification and
OCSP validation were enabled. A remote attacker could use this issue to
cause nginx to crash, resulting in a denial of service, or possibly modify
data in memory. (CVE-2026-40701)
It was discovered that nginx did not properly handle certain proxied
responses in the ngx_http_charset_module module. A
Red Hat
nginx: ngx_http_scgi_module: ngx_http_uwsgi_module: information disclosure and denial of service
vendor_redhat·2026-05-13·CVSS 8.3
CVE-2026-42946 [HIGH] CWE-823 nginx: ngx_http_scgi_module: ngx_http_uwsgi_module: information disclosure and denial of service
nginx: ngx_http_scgi_module: ngx_http_uwsgi_module: information disclosure and denial of service
A flaw was found in the ngx_http_scgi_module and ngx_http_uwsgi_module modules of NGINX. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker able to intercept and modify network traffic via a Man-In-The-Middle (MITM) attack and control the responses from an upstream server may be able to read sensitive data from the worker process or cause a denial of service by forcing the process to restart.
Statement: To exploit this issue, an attacker needs to be able to control the responses from SCGI or uWSGI backend servers via a Man-In-The-Middle (MITM) attack, limiting its exposure. Also, this vulnerability allows an attacker to read sensitive data from the memory of the worker pr
F5
CVE-2026-42946: A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive mem...
vendor_f5·2026-05-13·CVSS 8.3
CVE-2026-42946 [HIGH] CWE-789 CVE-2026-42946: A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive mem...
CVE-2026-42946: A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive mem...
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5 Advisory Articles: K000161027
F5 References: https://my.f5.com/manage/s/article/K000161027
VulDB
F5 NGINX Plus/NGINX Open Source ngx_http_scgi_module/ngx_http_uwsgi_module memory allocation (K000161027 / Nessus ID 314992)
vuldb·2026-06-16·CVSS 7.4
CVE-2026-42946 [HIGH] F5 NGINX Plus/NGINX Open Source ngx_http_scgi_module/ngx_http_uwsgi_module memory allocation (K000161027 / Nessus ID 314992)
A vulnerability classified as problematic has been found in F5 NGINX Plus and NGINX Open Source. Affected is an unknown function of the component ngx_http_scgi_module/ngx_http_uwsgi_module. The manipulation leads to uncontrolled memory allocation.
This vulnerability is listed as CVE-2026-42946. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
GHSA-fm65-xrrr-c358: A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of
ghsa_unreviewed·2026-05-13
CVE-2026-42946 [HIGH] CWE-789 GHSA-fm65-xrrr-c358: A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42946 nginx: ngx_http_scgi_module: ngx_http_uwsgi_module: information disclosure and denial of service
bugzilla·2026-05-13·CVSS 8.3
CVE-2026-42946 [HIGH] CVE-2026-42946 nginx: ngx_http_scgi_module: ngx_http_uwsgi_module: information disclosure and denial of service
CVE-2026-42946 nginx: ngx_http_scgi_module: ngx_http_uwsgi_module: information disclosure and denial of service
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to read the memory of the NGINX worker process or restart it. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Hackernews
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
blogs_hackernews·2026-05-14·CVSS 9.2
CVE-2026-42945 [CRITICAL] 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years.
The vulnerability, discovered by depthfirst , is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to achieve remote code execution or cause a denial-of-service (DoS) with crafted requests. It has been codenamed NGINX Rift .
"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_modul
2026-05-13
Published