Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-42945 Details

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2026:17417 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:17751 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:17752 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:17753 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:17790 redhat-SADP

see all 34 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-122Heap-based Buffer Overflow[email protected]
CWE-131Incorrect Calculation of Buffer Sizeredhat-SADP

Affected Products

ProductVersions

Change History

18 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-42945
NVD Published Date:
May 13, 2026
NVD Last Modified:
Sep 10, 2026
Source:
[email protected]
CVE-2026-42945 Details - Not Deferred