Skip to main content
EPSS 10.9%top 4.4%

NGINX ngx_http_rewrite_module vulnerability (CVE-2026-9256)

0
Critical
Published: 06/01/2026 (06/01/2026, 11:47:00 UTC)
Source: GCVE Database
Product: nginx

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected software

ubuntu/nginx
pkg:deb/ubuntu/nginx
Affected versions
=1.18.0-0ubuntu1.7+esm1=1.24.0-2ubuntu7.9=1.28.0-6ubuntu1.4=1.28.3-2ubuntu1.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:29:18 UTC

Technical Analysis

The vulnerability CVE-2026-40460 in Red Hat Hardened Images RPMs affects nginx when configured with the HTTP/3 QUIC module. It allows remote attackers to spoof source IP addresses, bypassing authorization and rate limiting controls. The issue is tracked under CWE-290 (Authentication Bypass) and is rated with a Red Hat CVSS v3.1 base score of 6.5 (medium severity). The advisory lists updated nginx RPMs version 1.30.2-1.hum1 for aarch64 and x86_64 architectures. The vendor recommends disabling the HTTP/3 QUIC module if it is not needed to mitigate the risk. The advisory does not explicitly confirm a patch but provides updated RPMs and guidance for mitigation.

Potential Impact

The vulnerability allows attackers to bypass authorization and rate limiting by spoofing their source IP address when the HTTP/3 QUIC module is enabled in nginx. This can lead to unauthorized access to resources or abuse of system resources. The impact on confidentiality is low, integrity is not affected, and availability impact is low. No known exploits are reported in the wild.

Mitigation Recommendations

Red Hat recommends disabling the HTTP/3 QUIC module in nginx configuration if it is not required by removing or commenting out the 'quic' parameter from the 'listen' directives in nginx.conf, followed by a graceful reload or restart of the nginx service. Users should apply the available update to nginx RPMs version 1.30.2-1.hum1 when possible. Patch status is not explicitly confirmed; check Red Hat advisories for the latest remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_base
Csaf Version
2.0
Publisher
Bundesamt für Sicherheit in der Informationstechnik
Advisory Id
WID-SEC-W-2026-1661
Cve Count
1
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a27e9958dd33fbd8516b1be

Added to database: 06/09/2026, 10:23:17 UTC

Last enriched: 08/16/2026, 17:29:18 UTC

Last updated: 09/15/2026, 05:01:37 UTC

Views: 125

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses