CVE-2026-42945
High · CVSS 8.1NGINX Plus and NGINX Open Source — Heap buffer overflow via PCRE capture in rewrite module (potential RCE)
- CVSS
- 8.1
- nvd
- EPSS
- 66.0%
- 99th pct
- KEV
- No
- Class
- oss containerizable
- CWE-122, CWE-131
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Search profile — drives PoC discovery
Ranked PoCs (44) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 873
- ★ 19
- ★ 1
- ★ 1josephfelix/CVE-2026-42945-nginx-rift candidatecontainerized · recent activitygh_search · Jupyter Notebook
- ★ 0
- ★ 0
- ★ 16
- ★ 15
- ★ 4
- ★ 3
- ★ 2
- ★ 1
- ★ 1
- ★ 1
- ★ 1
- ★ 1
- ★ 1
- ★ 1
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 45
- ★ 32
- ★ 18
- ★ 5
- ★ 3
- ★ 3
- ★ 3
- ★ 2
- ★ 1
- ★ 1
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Bitnami | nginx | 0.6.27 → 1.30.1 |
| Bitnami | nginx-gateway | 0.6.27 → 1.30.1 |
References
- https://my.f5.com/manage/s/article/K000161019
- https://depthfirst.com/nginx-rift
- https://github.com/DepthFirstDisclosures/Nginx-Rift
- https://access.redhat.com/errata/RHSA-2026:17417
- https://access.redhat.com/errata/RHSA-2026:17751
- https://access.redhat.com/errata/RHSA-2026:17752
- https://access.redhat.com/errata/RHSA-2026:17753
- https://access.redhat.com/errata/RHSA-2026:17790
- https://access.redhat.com/errata/RHSA-2026:17791
- https://access.redhat.com/errata/RHSA-2026:17792
- https://access.redhat.com/errata/RHSA-2026:17793
- https://access.redhat.com/errata/RHSA-2026:17794
Status: enriched · ingested 2026-06-27T06:00:38.000Z · profiled 2026-07-01T12:30:14.000Z