CRITICAL🇵🇱 Wersja polska

CVE-2026-42945

CVSS 9.2v4.0pub. 2026-05-13upd. 2026-08-25

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

🤖 AI Analysis
How it works

The vulnerability manifests when a rewrite directive is preceded by another rewrite, if, or set directive, and the PCRE regular expression contains an unnamed capture (e.g., $1, $2) in combination with a replacement string containing a question mark (?). An unauthenticated attacker can send crafted HTTP requests that trigger a heap buffer overflow in the NGINX worker process. Successful exploitation of the vulnerability requires certain conditions to be met that are partially independent of the attacker, which reflects a high level of attack complexity (AC:H in the CVSS vector).

Impact

In a typical attack scenario, an attacker can cause an NGINX worker process restart, resulting in temporary service unavailability. On systems with ASLR disabled or after bypassing it, remote code execution (RCE) is possible in the context of the NGINX worker process.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references (F5 article K000161019: https://my.f5.com/manage/s/article/K000161019). As an additional remedial measure, it is recommended to ensure that the ASLR mechanism is enabled on servers hosting NGINX, which significantly complicates effective code execution by an attacker.

Who is affected

NGINX Plus and NGINX Open Source — specific versions indicated in the vendor references (F5 article K000161019). Versions that have reached end of technical support (EoTS) are not subject to this assessment.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • F5 Dos

    APP
    F5
    4.8.04.3.0 – 4.7.0
  • F5 nginx Gateway Fabric

    APP
    F5
    1.3.0 – 1.6.22.0.0 – 2.5.1
  • F5 nginx Ingress Controller

    APP
    F5
    5.0.0 – 5.4.13.5.0 – 3.7.24.0.0 – 4.0.1
  • F5 nginx Instance Manager

    APP
    F5
    2.16.0 – 2.21.1
  • F5 nginx Open Source

    APP
    F5
    0.6.27 – 1.30.0
  • F5 nginx Plus

    APP
    F5
    r32 – r36
  • F5 Waf

    APP
    F5
    4.9.0 – 4.16.05.1.0 – 5.8.05.9.0 – 5.12.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassMemory
CWE
References

Related vulnerabilities

CVE-2026-42533CRITICAL9.2PL ✓same product

Heap buffer overflow w NGINX Plus i NGINX Open Source — DoS i możliwy RCE

CVE-2026-42530CRITICAL9.2PL ✓same product

Use-after-Free w module HTTP/3 QUIC NGINX — możliwość RCE

CVE-2026-42055CRITICAL9.2PL ✓same product

NGINX Plus/Open Source: heap buffer overflow w modułach HTTP/2 i gRPC

CVE-2026-9256CRITICAL9.2PL ✓same product

Heap buffer overflow w NGINX w module ngx_http_rewrite_module (RCE)

CVE-2026-52865HIGH7.1PL ✓same product

F5 NGINX Ingress Controller – DoS poprzez NULL pointer dereference (CWE-476)