Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42945

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 8.1

Описание

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests under specific rewrite configurations. This can lead to a heap buffer overflow in the NGINX worker process, which may result in arbitrary code execution if Address Space Layout Randomization (ASLR), a security technique to prevent exploitation, is disabled. Otherwise, this flaw causes a denial of service due to a restart of the NGINX worker process.

Отчет

Critical: This flaw in NGINX's ngx_http_rewrite_module can lead to arbitrary code execution due to a heap buffer overflow if Address Space Layout Randomization (ASLR) is disabled, or a denial of service otherwise. Exploitation requires specific, non-default NGINX rewrite configurations involving unnamed PCRE captures and a question mark in the replacement string.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp2/apicast-gateway-rhel8Affected
Red Hat Lightspeed proxy 1insights-proxy/insights-proxy-container-rhel9Affected
Red Hat Enterprise Linux 10nginxFixedRHSA-2026:1806318.05.2026
Red Hat Enterprise Linux 10nginxFixedRHSA-2026:1915919.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportnginxFixedRHSA-2026:1779015.05.2026
Red Hat Enterprise Linux 8nginxFixedRHSA-2026:1804118.05.2026
Red Hat Enterprise Linux 9nginxFixedRHSA-2026:1802918.05.2026
Red Hat Enterprise Linux 9nginxFixedRHSA-2026:1937119.05.2026
Red Hat Enterprise Linux 9nginxFixedRHSA-2026:1937219.05.2026
Red Hat Enterprise Linux 9nginxFixedRHSA-2026:1937419.05.2026

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2477116nginx: NGINX: Arbitrary Code Execution Vulnerability

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
nvd
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.1
msrc
3 месяца назад

NGINX ngx_http_rewrite_module vulnerability

CVSS3: 8.1
debian
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

rocky
2 месяца назад

Critical: nginx security update

8.1 High

CVSS3