Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2970 articles · 185100 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-42945KEVEXPLOITEDPATCHED
f5 · dos

NGINX ngx_http_rewrite_module vulnerability

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5dosR36, R32, 0.6.27

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
f5wafcve_cpe95%
f5nginx_instance_managercve_cpe95%
f5nginx_open_sourcecve_cpe95%
f5nginx_pluscve_cpe95%

References

  • https://my.f5.com/manage/s/article/K000161019(vendor-advisory, patch)

Related News (25 articles)

Tier D
The Hacker News5d ago
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
→ No new info (linked only)
Tier B
CERT-FR55d ago
Vulnérabilité dans les produits HPE Aruba Networking (15 juin 2026)
→ No new info (linked only)
Tier B
CCCS Canada60d ago
HPE security advisory (AV26-571)
→ No new info (linked only)
Tier B
CERT-FR75d ago
Bulletin d'actualité CERTFR-2026-ACT-023 (26 mai 2026)
→ No new info (linked only)
Tier D
Help Net Security76d ago
Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited
→ No new info (linked only)
Tier D
Heise Security81d ago
NGINX: DoS-Lücke wird angegriffen
→ No new info (linked only)
Tier D
Help Net Security82d ago
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945)
→ No new info (linked only)
Tier D
SecurityWeek82d ago
Exploitation of Critical NGINX Vulnerability Begins
→ No new info (linked only)
Tier B
CERT-FR83d ago
Bulletin d'actualité CERTFR-2026-ACT-022 (18 mai 2026)
→ No new info (linked only)
Tier D
The Hacker News83d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
→ No new info (linked only)
Tier D
SecurityWeek84d ago
PoC Code Published for Critical NGINX Vulnerability
→ No new info (linked only)
Tier A
Microsoft MSRC84d ago
CVE-2026-42945 NGINX ngx_http_rewrite_module vulnerability
→ No new info (linked only)
Tier B
BSI Advisories85d ago
[NEU] [hoch] NGINX Open Source and NGINX Plus: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security85d ago
F5 BIG-IP: Quartalssicherheitsupdate schließt zahlreiche Lücken
→ No new info (linked only)
Tier B
CERT-FR86d ago
Multiples vulnérabilités dans les produits F5 (15 mai 2026)
→ No new info (linked only)
Tier D
CSO Online86d ago
AI agent finds 18-year-old remote code execution flaw in Nginx
→ No new info (linked only)
Tier D
BleepingComputer86d ago
18-year-old NGINX vulnerability allows DoS, potential RCE
→ No new info (linked only)
Tier E
Reddit r/netsec86d ago
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
→ No new info (linked only)
Tier D
The Hacker News86d ago
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
→ No new info (linked only)
Tier E
Hacker News87d ago
CVE-2026-42945 – Critical heap buffer overflow in Nginx ngx_HTTP_rewrite_module
→ No new info (linked only)
Tier E
Lobsters Security87d ago
Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability
→ No new info (linked only)
Tier C
oss-security87d ago
NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945
→ No new info (linked only)
Tier C
VulDB87d ago
CVE-2026-42945 | F5 NGINX Plus/NGINX Open Source HTTP ngx_http_rewrite_module heap-based overflow (K000161019)
→ No new info (linked only)
Tier E
Hacker News87d ago
Nginx Rift: RCE via heap buffer overflow in rewrite module (CVE-2026-42945)
→ No new info (linked only)
Tier B
BSI Advisories120d ago
[UPDATE] [mittel] NGINX: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
37.0.0
CWECWE-122
PublishedMay 13, 2026
Last enriched76d agov13
Tags
CVE-2026-42945denial of servicedosnginxvulnerabilityCVE-2026-42946CVE-2026-40701CVE-2026-42934CVE-2026-41957Nginx RiftNGINX RiftCVE-2026-40460CVE-2026-42926
Trending Score65
Source articles25
Independent15
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-9256EXP
NGINX ngx_http_rewrite_module vulnerability
Trending: 7
LOWCVE-2026-60065EXP
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Trending: 2
HIGHCVE-2026-59762EXP
BIG-IP HTTP/2 vulnerability
Trending: 2
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
Trending: 1
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 13, 2026
Added to CISA KEV
May 13, 2026
Discovered by ZDM
May 13, 2026
Updated: description, severity, activelyExploited
May 13, 2026
Updated: affectedVersions, severity, cvssEstimate, patchAvailable, tags
May 13, 2026
Updated: affectedVersions, tags
May 14, 2026
Updated: description
May 15, 2026
Updated: tags
May 15, 2026
Updated: description
May 16, 2026
Updated: affectedVersions, cvssEstimate, exploitAvailable
May 17, 2026
Updated: description, tags
May 18, 2026
Updated: tags
May 18, 2026
Updated: description, affectedVersions
May 19, 2026
Updated: description, affectedVersions, severity, cvssEstimate, patchAvailable, tags
May 19, 2026
Updated: severity
May 24, 2026
Actively Exploited
Jul 20, 2026
Exploit Available
Jul 20, 2026
Patch Available
Jul 20, 2026

Version History

v13
Last enriched 76d ago
v13Tier D76d ago

Updated severity from HIGH to CRITICAL and added CVE-2026-42945 to tags.

severity
via Help Net Security
v12Tier D81d ago

Updated description with technical details, changed severity to CRITICAL, updated CVSS to 8.1, and added new affected versions and CVE IDs.

descriptionaffectedVersionsseveritycvssEstimatepatchAvailabletags
via Heise Security
v11Tier D81d ago

Updated description with new technical details, changed severity to CRITICAL, updated CVSS estimate to 8.1, and added new affected versions and patch version.

descriptionaffectedVersions
via Heise Security
v10Tier D82d ago

Updated severity from HIGH to CRITICAL and added new tag 'NGINX Rift'.

tags
via Help Net Security
v9Tier D82d ago

Updated description with additional technical details and added new tag 'Nginx Rift'.

descriptiontags
via SecurityWeek
v8Tier D83d ago

Updated product to include 'nginx open', changed affected versions to include '1.30.0', updated CVSS score to 9.2, marked exploit availability as true, and set patch available to null.

affectedVersionscvssEstimateexploitAvailable
via The Hacker News
v7Tier D84d ago

Updated description with detailed technical information, changed severity to CRITICAL, updated CVSS score to 9.2, and added new patch versions.

description
via SecurityWeek
v6Tier D85d ago

Updated severity to CRITICAL and added CVE-2026-41957 to tags.

tags
via Heise Security
v5Tier D86d ago

Updated severity to CRITICAL with a CVSS score of 9.2, added affected version 0.6.27, and provided a more detailed description of the vulnerability and exploitation potential.

description
via CSO Online
v4Tier D86d ago

Updated severity to CRITICAL, CVSS score to 9.2, and added new affected version and CVE IDs.

affectedVersionstags
via BleepingComputer
v3Tier C87d ago

Updated affected versions to include 1.30.0, changed severity to CRITICAL, updated CVSS score to 9.2, and added new tags.

affectedVersionsseveritycvssEstimatepatchAvailabletags
via oss-security
v2Tier C87d ago

Updated vendor to F5, product to NGINX Open Source, severity to CRITICAL, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v187d ago

Initial creation