Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3142 articles · 183352 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-42945KEVEXPLOITEDPATCHED
f5 · dos

NGINX ngx_http_rewrite_module vulnerability

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5dosR36, R32, 0.6.27

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
f5wafcve_cpe95%
f5nginx_instance_managercve_cpe95%
f5nginx_open_sourcecve_cpe95%
f5nginx_pluscve_cpe95%

References

  • https://my.f5.com/manage/s/article/K000161019(vendor-advisory, patch)

Related News (25 articles)

Tier D
The Hacker News4h ago
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
→ No new info (linked only)
Tier B
CERT-FR49d ago
Vulnérabilité dans les produits HPE Aruba Networking (15 juin 2026)
→ No new info (linked only)
Tier B
CCCS Canada54d ago
HPE security advisory (AV26-571)
→ No new info (linked only)
Tier B
CERT-FR69d ago
Bulletin d'actualité CERTFR-2026-ACT-023 (26 mai 2026)
→ No new info (linked only)
Tier D
Help Net Security71d ago
Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited
→ No new info (linked only)
Tier D
Heise Security76d ago
NGINX: DoS-Lücke wird angegriffen
→ No new info (linked only)
Tier D
Help Net Security77d ago
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945)
→ No new info (linked only)
Tier D
SecurityWeek77d ago
Exploitation of Critical NGINX Vulnerability Begins
→ No new info (linked only)
Tier B
CERT-FR77d ago
Bulletin d'actualité CERTFR-2026-ACT-022 (18 mai 2026)
→ No new info (linked only)
Tier D
The Hacker News78d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
→ No new info (linked only)
Tier D
SecurityWeek79d ago
PoC Code Published for Critical NGINX Vulnerability
→ No new info (linked only)
Tier A
Microsoft MSRC79d ago
CVE-2026-42945 NGINX ngx_http_rewrite_module vulnerability
→ No new info (linked only)
Tier B
BSI Advisories80d ago
[NEU] [hoch] NGINX Open Source and NGINX Plus: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security80d ago
F5 BIG-IP: Quartalssicherheitsupdate schließt zahlreiche Lücken
→ No new info (linked only)
Tier B
CERT-FR80d ago
Multiples vulnérabilités dans les produits F5 (15 mai 2026)
→ No new info (linked only)
Tier D
CSO Online80d ago
AI agent finds 18-year-old remote code execution flaw in Nginx
→ No new info (linked only)
Tier D
BleepingComputer81d ago
18-year-old NGINX vulnerability allows DoS, potential RCE
→ No new info (linked only)
Tier E
Reddit r/netsec81d ago
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
→ No new info (linked only)
Tier D
The Hacker News81d ago
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
→ No new info (linked only)
Tier E
Hacker News81d ago
CVE-2026-42945 – Critical heap buffer overflow in Nginx ngx_HTTP_rewrite_module
→ No new info (linked only)
Tier E
Lobsters Security81d ago
Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability
→ No new info (linked only)
Tier C
oss-security82d ago
NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945
→ No new info (linked only)
Tier C
VulDB82d ago
CVE-2026-42945 | F5 NGINX Plus/NGINX Open Source HTTP ngx_http_rewrite_module heap-based overflow (K000161019)
→ No new info (linked only)
Tier E
Hacker News82d ago
Nginx Rift: RCE via heap buffer overflow in rewrite module (CVE-2026-42945)
→ No new info (linked only)
Tier B
BSI Advisories115d ago
[UPDATE] [mittel] NGINX: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
37.0.0
CWECWE-122
PublishedMay 13, 2026
Last enriched71d agov13
Tags
CVE-2026-42945denial of servicedosnginxvulnerabilityCVE-2026-42946CVE-2026-40701CVE-2026-42934CVE-2026-41957Nginx RiftNGINX RiftCVE-2026-40460CVE-2026-42926
Trending Score141🔥
Source articles25
Independent15
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-9256EXP
NGINX ngx_http_rewrite_module vulnerability
Trending: 15
HIGHCVE-2026-59762EXP
BIG-IP HTTP/2 vulnerability
Trending: 5
LOWCVE-2026-60065EXP
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Trending: 4
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
Trending: 3
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 13, 2026
Added to CISA KEV
May 13, 2026
Discovered by ZDM
May 13, 2026
Updated: description, severity, activelyExploited
May 13, 2026
Updated: affectedVersions, severity, cvssEstimate, patchAvailable, tags
May 13, 2026
Updated: affectedVersions, tags
May 14, 2026
Updated: description
May 15, 2026
Updated: tags
May 15, 2026
Updated: description
May 16, 2026
Updated: affectedVersions, cvssEstimate, exploitAvailable
May 17, 2026
Updated: description, tags
May 18, 2026
Updated: tags
May 18, 2026
Updated: description, affectedVersions
May 19, 2026
Updated: description, affectedVersions, severity, cvssEstimate, patchAvailable, tags
May 19, 2026
Updated: severity
May 24, 2026
Actively Exploited
Jul 20, 2026
Exploit Available
Jul 20, 2026
Patch Available
Jul 20, 2026

Version History

v13
Last enriched 71d ago
v13Tier D71d ago

Updated severity from HIGH to CRITICAL and added CVE-2026-42945 to tags.

severity
via Help Net Security
v12Tier D76d ago

Updated description with technical details, changed severity to CRITICAL, updated CVSS to 8.1, and added new affected versions and CVE IDs.

descriptionaffectedVersionsseveritycvssEstimatepatchAvailabletags
via Heise Security
v11Tier D76d ago

Updated description with new technical details, changed severity to CRITICAL, updated CVSS estimate to 8.1, and added new affected versions and patch version.

descriptionaffectedVersions
via Heise Security
v10Tier D77d ago

Updated severity from HIGH to CRITICAL and added new tag 'NGINX Rift'.

tags
via Help Net Security
v9Tier D77d ago

Updated description with additional technical details and added new tag 'Nginx Rift'.

descriptiontags
via SecurityWeek
v8Tier D78d ago

Updated product to include 'nginx open', changed affected versions to include '1.30.0', updated CVSS score to 9.2, marked exploit availability as true, and set patch available to null.

affectedVersionscvssEstimateexploitAvailable
via The Hacker News
v7Tier D79d ago

Updated description with detailed technical information, changed severity to CRITICAL, updated CVSS score to 9.2, and added new patch versions.

description
via SecurityWeek
v6Tier D80d ago

Updated severity to CRITICAL and added CVE-2026-41957 to tags.

tags
via Heise Security
v5Tier D80d ago

Updated severity to CRITICAL with a CVSS score of 9.2, added affected version 0.6.27, and provided a more detailed description of the vulnerability and exploitation potential.

description
via CSO Online
v4Tier D81d ago

Updated severity to CRITICAL, CVSS score to 9.2, and added new affected version and CVE IDs.

affectedVersionstags
via BleepingComputer
v3Tier C81d ago

Updated affected versions to include 1.30.0, changed severity to CRITICAL, updated CVSS score to 9.2, and added new tags.

affectedVersionsseveritycvssEstimatepatchAvailabletags
via oss-security
v2Tier C82d ago

Updated vendor to F5, product to NGINX Open Source, severity to CRITICAL, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v182d ago

Initial creation