Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-42945: Nginx can crash or be hijacked by malformed request

CVE-2026-42945 · published 5 months ago
Summary

The Nginx web server (including Nginx Plus and the open‑source packages found in Debian, Ubuntu and other distributions) can be forced to crash and, in some cases, run attacker code when it processes specially crafted rewrite rules. This happens because a coding error lets a malicious request overflow memory in the worker process. Apply the latest security updates from your Linux distribution or upgrade to the newest Nginx release to protect your servers.

What to do
  • Update debian nginx to version 1.18.0-6.1+deb11u6.
  • Update debian nginx to version 1.22.1-9+deb12u7.
  • Update debian nginx to version 1.26.3-3+deb13u5.
  • Update canonical nginx to version 1.28.0-6ubuntu1.3.
  • Update canonical nginx to version 1.28.3-2ubuntu1.1.
  • Update nginx to version 1.30.1.
  • Update nginx-gateway to version 1.30.1.
  • Update bellsoft nginx to version 1.22.1-r5.
  • Update bellsoft nginx to version 1.28.3-r2.
  • Update canonical nginx to version 1.18.0-6ubuntu14.11.
  • Update canonical nginx to version 1.24.0-2ubuntu7.8.
  • Update alpine nginx to version 1.28.3-r1.
  • Update alpine nginx to version 1.26.3-r00072.
  • Update alpine rootio-nginx to version 1.26.3-r00072.
  • Update debian nginx to version 1.30.0-3.
  • Update nginx to version 1.26.3-r00073.
  • Update rootio-nginx to version 1.26.3-r00073.
  • Update nginx to version 1.20.2-r20072.
  • Update rootio-nginx to version 1.20.2-r20072.
  • Update nginx to version 1.26.3-r1.
  • Update nginx to version 1.28.3-r1.
  • Update nginx to version 1.30.1-r0.
  • Update nginx to version 1.20.2-r20073.
  • Update rootio-nginx to version 1.20.2-r20073.
  • Update f5 nginx plus to version R36 P4 or later.
  • Update f5 nginx open source to version 1.30.1 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian nginx < 1.18.0-6.1+deb11u6
Fix: upgrade to 1.18.0-6.1+deb11u6
Debian:12 debian nginx < 1.22.1-9+deb12u7
Fix: upgrade to 1.22.1-9+deb12u7
Debian:13 debian nginx < 1.26.3-3+deb13u5
Fix: upgrade to 1.26.3-3+deb13u5
Ubuntu:25.10 canonical nginx < 1.28.0-6ubuntu1.3
Fix: upgrade to 1.28.0-6ubuntu1.3
Ubuntu:26.04:LTS canonical nginx < 1.28.3-2ubuntu1.1
Fix: upgrade to 1.28.3-2ubuntu1.1
Debian:14 debian nginx < 1.30.0-3
Fix: upgrade to 1.30.0-3
Bitnami – nginx >= 0.6.27, < 1.30.1
Fix: upgrade to 1.30.1
Bitnami – nginx-gateway >= 0.6.27, < 1.30.1
Fix: upgrade to 1.30.1
Alpaquita:23 bellsoft nginx >= 1.22.1-r0, < 1.22.1-r5
Fix: upgrade to 1.22.1-r5
Alpaquita:25 bellsoft nginx >= 1.28.0-r3, < 1.28.3-r2
Fix: upgrade to 1.28.3-r2
Ubuntu:Pro:14.04:LTS canonical nginx All versions
Ubuntu:Pro:16.04:LTS canonical nginx All versions
Ubuntu:Pro:18.04:LTS canonical nginx All versions
Ubuntu:Pro:20.04:LTS canonical nginx All versions
Ubuntu:22.04:LTS canonical nginx < 1.18.0-6ubuntu14.11
Fix: upgrade to 1.18.0-6ubuntu14.11
Ubuntu:24.04:LTS canonical nginx < 1.24.0-2ubuntu7.8
Fix: upgrade to 1.24.0-2ubuntu7.8
– f5 dos >= 4.3.0, <= 4.7.0
4.8.0
cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*
– f5 nginx_gateway_fabric >= 1.3.0, <= 1.6.2
>= 2.0.0, <= 2.5.1
cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*
– f5 nginx_ingress_controller >= 3.5.0, <= 3.7.2
>= 4.0.0, <= 4.0.1
>= 5.0.0, <= 5.4.1
cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*
– f5 nginx_instance_manager >= 2.16.0, <= 2.21.1
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
– f5 nginx_open_source >= 0.6.27, <= 1.30.0
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
– f5 nginx_plus >= r32, <= r36
cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:*
– f5 waf >= 4.9.0, <= 4.16.0
>= 5.1.0, <= 5.8.0
>= 5.9.0, <= 5.12.1
cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*
– f5 nginx plus < R36 P4
– f5 nginx open source < 1.30.1
Alpine:v3.22 alpine nginx < 1.28.3-r1
Fix: upgrade to 1.28.3-r1
Alpine:v3.23 alpine nginx < 1.28.3-r1
Fix: upgrade to 1.28.3-r1
Root:Alpine:3.20 alpine nginx < 1.26.3-r00072
Fix: upgrade to 1.26.3-r00072
Root:Alpine:3.20 alpine rootio-nginx < 1.26.3-r00072
Fix: upgrade to 1.26.3-r00072
Root:Alpine:3.20 – nginx < 1.26.3-r00073
Fix: upgrade to 1.26.3-r00073
Root:Alpine:3.20 – rootio-nginx < 1.26.3-r00073
Fix: upgrade to 1.26.3-r00073
Root:Alpine:3.15 – nginx < 1.20.2-r20072
< 1.20.2-r20073
Fix: upgrade to 1.20.2-r20072
Root:Alpine:3.15 – rootio-nginx < 1.20.2-r20072
< 1.20.2-r20073
Fix: upgrade to 1.20.2-r20072
Alpine:v3.21 – nginx < 1.26.3-r1
Fix: upgrade to 1.26.3-r1
Alpine:v3.22 – nginx < 1.28.3-r1
Fix: upgrade to 1.28.3-r1
Alpine:v3.24 – nginx < 1.30.1-r0
Fix: upgrade to 1.30.1-r0
Original advisory text
CVE-2026-42945 in nginx - Patched by Root
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
3% chance of attack within 30 days
Type
CWE-122Heap-based Buffer Overflow
CWE-131Incorrect Calculation of Buffer Size
Timeline
Published13 May 2026
Updated9 Oct 2026
First seen13 May 2026
Track software like this
Free during beta