CVE-2026-42945

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161019 Mitigation Vendor Advisory
https://depthfirst.com/nginx-rift Mitigation Technical Description Third Party Advisory
https://github.com/DepthFirstDisclosures/Nginx-Rift Exploit Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:17417
https://access.redhat.com/errata/RHSA-2026:17751
https://access.redhat.com/errata/RHSA-2026:17752
https://access.redhat.com/errata/RHSA-2026:17753
https://access.redhat.com/errata/RHSA-2026:17790
https://access.redhat.com/errata/RHSA-2026:17791
https://access.redhat.com/errata/RHSA-2026:17792
https://access.redhat.com/errata/RHSA-2026:17793
https://access.redhat.com/errata/RHSA-2026:17794
https://access.redhat.com/errata/RHSA-2026:18029
https://access.redhat.com/errata/RHSA-2026:18041
https://access.redhat.com/errata/RHSA-2026:18063
https://access.redhat.com/errata/RHSA-2026:19159
https://access.redhat.com/errata/RHSA-2026:19371
https://access.redhat.com/errata/RHSA-2026:19372
https://access.redhat.com/errata/RHSA-2026:19374
https://access.redhat.com/errata/RHSA-2026:20442
https://access.redhat.com/errata/RHSA-2026:20444
https://access.redhat.com/errata/RHSA-2026:21275
https://access.redhat.com/errata/RHSA-2026:22382
https://access.redhat.com/errata/RHSA-2026:22383
https://access.redhat.com/errata/RHSA-2026:22388
https://access.redhat.com/errata/RHSA-2026:22389
https://access.redhat.com/errata/RHSA-2026:22390
https://access.redhat.com/errata/RHSA-2026:22393
https://access.redhat.com/errata/RHSA-2026:22394
https://access.redhat.com/errata/RHSA-2026:22396
https://access.redhat.com/errata/RHSA-2026:58981
https://access.redhat.com/security/cve/CVE-2026-42945
https://bugzilla.redhat.com/show_bug.cgi?id=2477116
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*

History

No history.

Information

Published : 2026-05-13 16:16

Updated : 2026-09-10 13:20


NVD link : CVE-2026-42945

Mitre link : CVE-2026-42945

CVE.ORG link : CVE-2026-42945


JSON object : View

Products Affected

f5

  • nginx_open_source
  • nginx_ingress_controller
  • nginx_plus
  • waf
  • nginx_instance_manager
  • dos
  • nginx_gateway_fabric
CWE
CWE-122

Heap-based Buffer Overflow

CWE-131

Incorrect Calculation of Buffer Size