CVE-2026-42945: CWE-122 Heap-based Buffer Overflow. in F5 NGINX Plus
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AI Analysis
Technical Summary
CVE-2026-42945 is a critical vulnerability in NGINX's ngx_http_rewrite_module where improper buffer size calculation leads to a heap buffer overflow. An unauthenticated attacker can exploit this by sending crafted HTTP requests under specific rewrite configurations that use unnamed PCRE captures and a question mark in the replacement string. This overflow can cause a denial of service by crashing the NGINX worker process or, if ASLR is disabled, enable arbitrary code execution. Red Hat has released updated RPM packages including nginx-1.30.1-1.hum1 to fix this issue. The vulnerability is tracked under CWE-131 (Incorrect Calculation of Buffer Size) and has a Red Hat CVSS v3.1 base score of 8.1.
Potential Impact
The vulnerability allows unauthenticated attackers to cause denial of service by crashing or restarting the NGINX worker process under default conditions. If ASLR is disabled, it can lead to arbitrary code execution, posing a critical risk to affected systems. This impacts confidentiality, integrity, and availability of the affected NGINX service. Exploitation requires specific, non-default rewrite configurations, limiting the attack surface to certain deployments.
Mitigation Recommendations
Red Hat has released updated RPM packages (nginx-1.30.1-1.hum1 and related modules) that fix this vulnerability. Users should apply these official updates promptly to remediate the issue. No alternative mitigations are specified in the advisory. Since this is a critical security flaw, patching is the recommended and effective mitigation.
CVE-2026-42945: CWE-122 Heap-based Buffer Overflow. in F5 NGINX Plus
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS v3.1
Score 8.1high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-42945 is a critical vulnerability in NGINX's ngx_http_rewrite_module where improper buffer size calculation leads to a heap buffer overflow. An unauthenticated attacker can exploit this by sending crafted HTTP requests under specific rewrite configurations that use unnamed PCRE captures and a question mark in the replacement string. This overflow can cause a denial of service by crashing the NGINX worker process or, if ASLR is disabled, enable arbitrary code execution. Red Hat has released updated RPM packages including nginx-1.30.1-1.hum1 to fix this issue. The vulnerability is tracked under CWE-131 (Incorrect Calculation of Buffer Size) and has a Red Hat CVSS v3.1 base score of 8.1.
Potential Impact
The vulnerability allows unauthenticated attackers to cause denial of service by crashing or restarting the NGINX worker process under default conditions. If ASLR is disabled, it can lead to arbitrary code execution, posing a critical risk to affected systems. This impacts confidentiality, integrity, and availability of the affected NGINX service. Exploitation requires specific, non-default rewrite configurations, limiting the attack surface to certain deployments.
Mitigation Recommendations
Red Hat has released updated RPM packages (nginx-1.30.1-1.hum1 and related modules) that fix this vulnerability. Users should apply these official updates promptly to remediate the issue. No alternative mitigations are specified in the advisory. Since this is a critical security flaw, patching is the recommended and effective mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20442
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a160991e29bf47b50654f3a
Added to database: 05/26/2026, 20:58:57 UTC
Last enriched: 08/16/2026, 18:02:10 UTC
Last updated: 09/13/2026, 07:04:37 UTC
Views: 191
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.