CVE-2026-9256 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A heap buffer overflow vulnerability has been identified in the ngx_http_rewrite_module of NGINX Plus and NGINX Open Source. This issue arises when a rewrite directive employs a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures, and a replacement string that references multiple such captures in a redirect or arguments context. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests, which may lead to a denial-of-service condition by causing the NGINX worker process to crash and restart. Furthermore, on systems with Address Space Layout Randomization (ASLR) disabled or where ASLR can be bypassed, this vulnerability could be exploited to execute arbitrary code.
To address this vulnerability, users should upgrade to NGINX versions 1.31.1 or 1.30.2 for NGINX Open Source, and version 37.0.1.1 for NGINX Plus. For NGINX Ingress Controller, versions 5.4.2 and 4.0.1 are recommended. Users can also mitigate this vulnerability by using named captures instead of unnamed captures in rewrite directives.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | redhat-SADP |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx open source | >= 0.1.17, <= 0.9.7 >= 1.0.0, < 1.30.2 1.31.0 |
CPE
Remediation
| |
| f5 nginx plus | >= r33, < r36 37.0.0.1 r32 - r32 p1 r32 p2 r32 p3 r32 p4 r32 p5 r32 p6 r36 - r36 p1 r36 p2 r36 p3 r36 p4 |
CPE
Remediation
| |
| f5 dos | >= 4.3.0, <= 4.7.0 4.9.0 |
CPE
Remediation
| |
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, < 2.6.2 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, < 5.4.3 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.17.0, < 2.22.1 |
CPE
Remediation
| |
| f5 waf | >= 4.10.0, <= 4.16.0 >= 5.2.0, <= 5.8.0 >= 5.9.0, <= 5.13.0 |
CPE
Remediation
| |
| redhat discovery | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat update infrastructure | >= 5.0, < 5.2 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | CVE Modified | redhat-SADP |
| Aug 11, 2026 | Modified Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | redhat-SADP |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 18, 2026 | CVE Modified | CVE |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| May 23, 2026 | CVE Modified | CVE |
| May 22, 2026 | New CVE Received | [email protected] |