← Back to browse · API

CVE-2026-42945

Severity
CRITICAL
CVSS
9.2
EPSS
0.66039
Risk score
59.91
CISA KEV
No
PoC
Yes
Published
2026-05-13
Modified
2026-07-20
First seen
2026-08-07
Aliases
EUVD-2026-30010, GHSA-GCGV-V5GF-C543
Products
F5:NGINX Open Source 0.6.27 <1.30.1, F5:NGINX Plus R32 <R32 P6, F5:NGINX Plus R36 <R36 P4
Sources
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-42945
euvd EUVD-2026-30010

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References