NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Vendor | Product | Versions |
|---|---|---|
| f5 | dos | R36, R32, 0.6.27 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| canonical | ubuntu linux | cert_advisory | 90% |
| f5 | waf | cve_cpe | 95% |
| f5 | nginx_instance_manager | cve_cpe | 95% |
| f5 | nginx_open_source | cve_cpe | 95% |
| f5 | nginx_plus | cve_cpe | 95% |
Updated severity from HIGH to CRITICAL and added CVE-2026-42945 to tags.
Updated description with technical details, changed severity to CRITICAL, updated CVSS to 8.1, and added new affected versions and CVE IDs.
Updated description with new technical details, changed severity to CRITICAL, updated CVSS estimate to 8.1, and added new affected versions and patch version.
Updated severity from HIGH to CRITICAL and added new tag 'NGINX Rift'.
Updated description with additional technical details and added new tag 'Nginx Rift'.
Updated product to include 'nginx open', changed affected versions to include '1.30.0', updated CVSS score to 9.2, marked exploit availability as true, and set patch available to null.
Updated description with detailed technical information, changed severity to CRITICAL, updated CVSS score to 9.2, and added new patch versions.
Updated severity to CRITICAL and added CVE-2026-41957 to tags.
Updated severity to CRITICAL with a CVSS score of 9.2, added affected version 0.6.27, and provided a more detailed description of the vulnerability and exploitation potential.
Updated severity to CRITICAL, CVSS score to 9.2, and added new affected version and CVE IDs.
Updated affected versions to include 1.30.0, changed severity to CRITICAL, updated CVSS score to 9.2, and added new tags.
Updated vendor to F5, product to NGINX Open Source, severity to CRITICAL, and noted that there is no exploit available.
Initial creation