CVE-2026-42945

HIGH

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS v3.1 Score

8.1
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Complexity
HIGH
Privileges
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Published: 5/13/2026Modified: 8/17/2026

Related Intelligence (1)

References (33)

https://my.f5.com/manage/s/article/K000161019MitigationVendor Advisoryhttps://depthfirst.com/nginx-riftMitigationTechnical Descriptionhttps://github.com/DepthFirstDisclosures/Nginx-RiftExploitThird Party Advisoryhttps://access.redhat.com/errata/RHSA-2026:17417https://access.redhat.com/errata/RHSA-2026:17751https://access.redhat.com/errata/RHSA-2026:17752https://access.redhat.com/errata/RHSA-2026:17753https://access.redhat.com/errata/RHSA-2026:17790https://access.redhat.com/errata/RHSA-2026:17791https://access.redhat.com/errata/RHSA-2026:17792https://access.redhat.com/errata/RHSA-2026:17793https://access.redhat.com/errata/RHSA-2026:17794https://access.redhat.com/errata/RHSA-2026:18029https://access.redhat.com/errata/RHSA-2026:18041https://access.redhat.com/errata/RHSA-2026:18063https://access.redhat.com/errata/RHSA-2026:19159https://access.redhat.com/errata/RHSA-2026:19371https://access.redhat.com/errata/RHSA-2026:19372https://access.redhat.com/errata/RHSA-2026:19374https://access.redhat.com/errata/RHSA-2026:20442https://access.redhat.com/errata/RHSA-2026:20444https://access.redhat.com/errata/RHSA-2026:21275https://access.redhat.com/errata/RHSA-2026:22382https://access.redhat.com/errata/RHSA-2026:22383https://access.redhat.com/errata/RHSA-2026:22388https://access.redhat.com/errata/RHSA-2026:22389https://access.redhat.com/errata/RHSA-2026:22390https://access.redhat.com/errata/RHSA-2026:22393https://access.redhat.com/errata/RHSA-2026:22394https://access.redhat.com/errata/RHSA-2026:22396https://access.redhat.com/security/cve/CVE-2026-42945https://bugzilla.redhat.com/show_bug.cgi?id=2477116https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json