NGINX ngx_http_rewrite_module vulnerability (CVE-2026-9256)
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AI Analysis
Technical Summary
The vulnerability CVE-2026-40460 in Red Hat Hardened Images RPMs affects nginx when configured with the HTTP/3 QUIC module. It allows remote attackers to spoof source IP addresses, bypassing authorization and rate limiting controls. The issue is tracked under CWE-290 (Authentication Bypass) and is rated with a Red Hat CVSS v3.1 base score of 6.5 (medium severity). The advisory lists updated nginx RPMs version 1.30.2-1.hum1 for aarch64 and x86_64 architectures. The vendor recommends disabling the HTTP/3 QUIC module if it is not needed to mitigate the risk. The advisory does not explicitly confirm a patch but provides updated RPMs and guidance for mitigation.
Potential Impact
The vulnerability allows attackers to bypass authorization and rate limiting by spoofing their source IP address when the HTTP/3 QUIC module is enabled in nginx. This can lead to unauthorized access to resources or abuse of system resources. The impact on confidentiality is low, integrity is not affected, and availability impact is low. No known exploits are reported in the wild.
Mitigation Recommendations
Red Hat recommends disabling the HTTP/3 QUIC module in nginx configuration if it is not required by removing or commenting out the 'quic' parameter from the 'listen' directives in nginx.conf, followed by a graceful reload or restart of the nginx service. Users should apply the available update to nginx RPMs version 1.30.2-1.hum1 when possible. Patch status is not explicitly confirmed; check Red Hat advisories for the latest remediation guidance.
NGINX ngx_http_rewrite_module vulnerability (CVE-2026-9256)
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected software
pkg:deb/ubuntu/nginxRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-40460 in Red Hat Hardened Images RPMs affects nginx when configured with the HTTP/3 QUIC module. It allows remote attackers to spoof source IP addresses, bypassing authorization and rate limiting controls. The issue is tracked under CWE-290 (Authentication Bypass) and is rated with a Red Hat CVSS v3.1 base score of 6.5 (medium severity). The advisory lists updated nginx RPMs version 1.30.2-1.hum1 for aarch64 and x86_64 architectures. The vendor recommends disabling the HTTP/3 QUIC module if it is not needed to mitigate the risk. The advisory does not explicitly confirm a patch but provides updated RPMs and guidance for mitigation.
Potential Impact
The vulnerability allows attackers to bypass authorization and rate limiting by spoofing their source IP address when the HTTP/3 QUIC module is enabled in nginx. This can lead to unauthorized access to resources or abuse of system resources. The impact on confidentiality is low, integrity is not affected, and availability impact is low. No known exploits are reported in the wild.
Mitigation Recommendations
Red Hat recommends disabling the HTTP/3 QUIC module in nginx configuration if it is not required by removing or commenting out the 'quic' parameter from the 'listen' directives in nginx.conf, followed by a graceful reload or restart of the nginx service. Users should apply the available update to nginx RPMs version 1.30.2-1.hum1 when possible. Patch status is not explicitly confirmed; check Red Hat advisories for the latest remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_base
- Csaf Version
- 2.0
- Publisher
- Bundesamt für Sicherheit in der Informationstechnik
- Advisory Id
- WID-SEC-W-2026-1661
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a27e9958dd33fbd8516b1be
Added to database: 06/09/2026, 10:23:17 UTC
Last enriched: 08/16/2026, 17:29:18 UTC
Last updated: 09/15/2026, 05:01:37 UTC
Views: 125
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.