CVE-2026-42945

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K000161019 Mitigation Vendor Advisory
https://depthfirst.com/nginx-rift Mitigation Technical Description Third Party Advisory
https://github.com/DepthFirstDisclosures/Nginx-Rift Exploit Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:17417
https://access.redhat.com/errata/RHSA-2026:17751
https://access.redhat.com/errata/RHSA-2026:17752
https://access.redhat.com/errata/RHSA-2026:17753
https://access.redhat.com/errata/RHSA-2026:17790
https://access.redhat.com/errata/RHSA-2026:17791
https://access.redhat.com/errata/RHSA-2026:17792
https://access.redhat.com/errata/RHSA-2026:17793
https://access.redhat.com/errata/RHSA-2026:17794
https://access.redhat.com/errata/RHSA-2026:18029
https://access.redhat.com/errata/RHSA-2026:18041
https://access.redhat.com/errata/RHSA-2026:18063
https://access.redhat.com/errata/RHSA-2026:19159
https://access.redhat.com/errata/RHSA-2026:19371
https://access.redhat.com/errata/RHSA-2026:19372
https://access.redhat.com/errata/RHSA-2026:19374
https://access.redhat.com/errata/RHSA-2026:20442
https://access.redhat.com/errata/RHSA-2026:20444
https://access.redhat.com/errata/RHSA-2026:21275
https://access.redhat.com/errata/RHSA-2026:22382
https://access.redhat.com/errata/RHSA-2026:22383
https://access.redhat.com/errata/RHSA-2026:22388
https://access.redhat.com/errata/RHSA-2026:22389
https://access.redhat.com/errata/RHSA-2026:22390
https://access.redhat.com/errata/RHSA-2026:22393
https://access.redhat.com/errata/RHSA-2026:22394
https://access.redhat.com/errata/RHSA-2026:22396
https://access.redhat.com/security/cve/CVE-2026-42945
https://bugzilla.redhat.com/show_bug.cgi?id=2477116
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*

History

27 Jun 2026, 05:16

Type Values Removed Values Added
CWE CWE-131
References
  • () https://access.redhat.com/errata/RHSA-2026:17417 -
  • () https://access.redhat.com/errata/RHSA-2026:17751 -
  • () https://access.redhat.com/errata/RHSA-2026:17752 -
  • () https://access.redhat.com/errata/RHSA-2026:17753 -
  • () https://access.redhat.com/errata/RHSA-2026:17790 -
  • () https://access.redhat.com/errata/RHSA-2026:17791 -
  • () https://access.redhat.com/errata/RHSA-2026:17792 -
  • () https://access.redhat.com/errata/RHSA-2026:17793 -
  • () https://access.redhat.com/errata/RHSA-2026:17794 -
  • () https://access.redhat.com/errata/RHSA-2026:18029 -
  • () https://access.redhat.com/errata/RHSA-2026:18041 -
  • () https://access.redhat.com/errata/RHSA-2026:18063 -
  • () https://access.redhat.com/errata/RHSA-2026:19159 -
  • () https://access.redhat.com/errata/RHSA-2026:19371 -
  • () https://access.redhat.com/errata/RHSA-2026:19372 -
  • () https://access.redhat.com/errata/RHSA-2026:19374 -
  • () https://access.redhat.com/errata/RHSA-2026:20442 -
  • () https://access.redhat.com/errata/RHSA-2026:20444 -
  • () https://access.redhat.com/errata/RHSA-2026:21275 -
  • () https://access.redhat.com/errata/RHSA-2026:22382 -
  • () https://access.redhat.com/errata/RHSA-2026:22383 -
  • () https://access.redhat.com/errata/RHSA-2026:22388 -
  • () https://access.redhat.com/errata/RHSA-2026:22389 -
  • () https://access.redhat.com/errata/RHSA-2026:22390 -
  • () https://access.redhat.com/errata/RHSA-2026:22393 -
  • () https://access.redhat.com/errata/RHSA-2026:22394 -
  • () https://access.redhat.com/errata/RHSA-2026:22396 -
  • () https://access.redhat.com/security/cve/CVE-2026-42945 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2477116 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json -

18 Jun 2026, 14:12

Type Values Removed Values Added
CPE cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
References () https://my.f5.com/manage/s/article/K000161019 - () https://my.f5.com/manage/s/article/K000161019 - Mitigation, Vendor Advisory
References () https://depthfirst.com/nginx-rift - () https://depthfirst.com/nginx-rift - Mitigation, Technical Description, Third Party Advisory
References () https://github.com/DepthFirstDisclosures/Nginx-Rift - () https://github.com/DepthFirstDisclosures/Nginx-Rift - Exploit, Third Party Advisory
First Time F5 nginx Open Source
F5 nginx Ingress Controller
F5 nginx Instance Manager
F5 dos
F5 waf
F5 nginx Gateway Fabric
F5 nginx Plus
F5

21 May 2026, 19:16

Type Values Removed Values Added
Summary (en) NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. (en) NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

14 May 2026, 20:17

Type Values Removed Values Added
References
  • () https://github.com/DepthFirstDisclosures/Nginx-Rift -

14 May 2026, 02:17

Type Values Removed Values Added
References
  • () https://depthfirst.com/nginx-rift -

13 May 2026, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-07-15 02:21


NVD link : CVE-2026-42945

Mitre link : CVE-2026-42945

CVE.ORG link : CVE-2026-42945


JSON object : View

Products Affected

f5

  • dos
  • nginx_open_source
  • nginx_plus
  • nginx_ingress_controller
  • nginx_gateway_fabric
  • nginx_instance_manager
  • waf
CWE
CWE-122

Heap-based Buffer Overflow

CWE-131

Incorrect Calculation of Buffer Size