CVE-2026-42945 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A heap buffer overflow vulnerability has been identified in the ngx_http_rewrite_module of NGINX Plus and NGINX Open Source. This issue arises when the rewrite directive is used with unnamed Perl-Compatible Regular Expression (PCRE) captures in a way that includes a question mark in the replacement string. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests, potentially leading to a denial-of-service condition by causing the NGINX worker process to crash and restart. Furthermore, on systems with Address Space Layout Randomization (ASLR) disabled, this vulnerability could be exploited for arbitrary code execution.
To address this vulnerability, users are advised to upgrade to NGINX Plus version 37.0.0 or NGINX Open Source versions 1.31.0 or 1.30.1. For NGINX Instance Manager, version 2.21.1 or later should be used. If using NGINX App Protect WAF, upgrade to version 5.9.0 or later. For NGINX Gateway Fabric, version 2.5.1 or later is recommended. To mitigate the vulnerability without upgrading, use named captures instead of unnamed captures in rewrite directives.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
| CWE-131 | Incorrect Calculation of Buffer Size | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| f5 dos | >= 4.3.0, <= 4.7.0 4.8.0 |
CPE
Remediation
| |
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.5.1 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.4.1 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.16.0, <= 2.21.1 |
CPE
Remediation
| |
| f5 nginx open source | >= 0.6.27, <= 1.30.0 |
CPE
Remediation
| |
| f5 nginx plus | >= r32, <= r36 |
CPE
Remediation
| |
| f5 waf | >= 4.9.0, <= 4.16.0 >= 5.1.0, <= 5.8.0 >= 5.9.0, <= 5.12.1 |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | redhat-SADP |
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | CVE |
| Sep 7, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 11, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 27, 2026 | CVE Modified | redhat-SADP |
| Jun 18, 2026 | Reanalysis | [email protected] |
| Jun 17, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 21, 2026 | CVE Modified | [email protected] |
| May 14, 2026 | CVE Modified | CVE |
| May 14, 2026 | CVE Modified | CVE |
| May 13, 2026 | New CVE Received | [email protected] |