Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3136 articles · 183352 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-9256EXPLOITEDPATCHED
f5 · nginx_open_source

NGINX ngx_http_rewrite_module vulnerability

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx_open_source37.0, R36, R32, 1.31.0, 1.30.0, 0.1.17

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
f5nginx_pluscve_cpe95%
nginxnginx pluscert_advisory90%
nginxnginxcert_advisory90%
oracleoracle communicationscert_advisory90%

References

  • https://my.f5.com/manage/s/article/K000161377(vendor-advisory)

Related News (11 articles)

Tier B
BSI Advisories12d ago
[NEU] [hoch] Oracle Communications: Mehrere Schwachstellen
→ No new info (linked only)
Tier A
Microsoft MSRC68d ago
CVE-2026-9256 NGINX ngx_http_rewrite_module vulnerability
→ No new info (linked only)
Tier D
Heise Security69d ago
DoS- und Schadcode-Attacken auf NGINX-Webserver vorstellbar
→ No new info (linked only)
Tier B
BSI Advisories69d ago
[NEU] [hoch] NGINX Open Source und NGINX Plus: Schwachstelle ermöglicht Denial of Service und potenziell Codeausführung
→ No new info (linked only)
Tier B
CERT-FR69d ago
Vulnérabilité dans Nginx (26 mai 2026)
→ No new info (linked only)
Tier B
CCCS Canada70d ago
cPanel security advisory (AV26-508)
→ No new info (linked only)
Tier E
Hacker News72d ago
CVE-2026-9256: Nginx 1.31.1 and 1.30.1
→ No new info (linked only)
Tier C
oss-security72d ago
NGINX ngx_http_rewrite_module buffer overflow (CVE-2026-9256)
→ No new info (linked only)
Tier E
Reddit r/netsec72d ago
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
→ No new info (linked only)
Tier B
CCCS Canada73d ago
F5 security advisory (AV26-501)
→ No new info (linked only)
Tier C
VulDB73d ago
CVE-2026-9256 | F5 NGINX Plus/NGINX Open Source prior 37.0.1.1/R32 P7/R36 P5 ngx_http_rewrite_module heap-based overflow (K000161377)
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
37.0.1.1
CWECWE-122
PublishedMay 22, 2026
Last enriched69d agov7
Tags
F5NGINXsecurity advisoryDenial of ServiceCVE-2026-9256
Trending Score15
Source articles11
Independent9
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-42945EXPKEV
NGINX ngx_http_rewrite_module vulnerability
Trending: 141
HIGHCVE-2026-59762EXP
BIG-IP HTTP/2 vulnerability
Trending: 5
LOWCVE-2026-60065EXP
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Trending: 4
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
Trending: 3
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 22, 2026
Discovered by ZDM
May 22, 2026
Updated: description, severity, activelyExploited
May 22, 2026
Updated: affectedVersions, tags
May 22, 2026
Updated: affectedVersions, cweIds, exploitAvailable, patchAvailable
May 25, 2026
Updated: description, severity, tags
May 26, 2026
Updated: affectedVersions
May 26, 2026
Updated: affectedVersions, patchAvailable, tags
May 26, 2026
Actively Exploited
Jul 24, 2026
Exploit Available
Jul 24, 2026
Patch Available
Jul 24, 2026

Version History

v7
Last enriched 69d ago
v7Tier B69d ago

Updated affected versions to include 1.30.1 and 37.0.1.1, and added new tag CVE-2026-9256.

affectedVersionspatchAvailabletags
via CERT-FR
v6Tier D69d ago

Updated affected versions to include 1.30.2, 37.0.11, R36 P5, R32 P7 and provided a more detailed description of the vulnerability's impact.

affectedVersions
via Heise Security
v5Tier B69d ago

Updated description to include Denial of Service potential and changed severity to CRITICAL.

descriptionseveritytags
via BSI Advisories
v4Tier B70d ago

Updated vendor to cPanel, product to ea-nginx, added affected version v1.31.1, and included CVE-2026-9256.

affectedVersionscweIdsexploitAvailablepatchAvailable
via CCCS Canada
v3Tier B73d ago

Added new affected versions for various NGINX products and included relevant tags.

affectedVersionstags
via CCCS Canada
v2Tier C73d ago

Updated vendor to F5, product to NGINX Open Source, changed severity to CRITICAL, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v173d ago

Initial creation