Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-42945: Nginx can crash or be hijacked by malformed request
CVE-2026-42945 · published 5 months ago
Summary
The Nginx web server (including Nginx Plus and the open‑source packages found in Debian, Ubuntu and other distributions) can be forced to crash and, in some cases, run attacker code when it processes specially crafted rewrite rules. This happens because a coding error lets a malicious request overflow memory in the worker process. Apply the latest security updates from your Linux distribution or upgrade to the newest Nginx release to protect your servers.
What to do
- Update debian nginx to version 1.18.0-6.1+deb11u6.
- Update debian nginx to version 1.22.1-9+deb12u7.
- Update debian nginx to version 1.26.3-3+deb13u5.
- Update canonical nginx to version 1.28.0-6ubuntu1.3.
- Update canonical nginx to version 1.28.3-2ubuntu1.1.
- Update nginx to version 1.30.1.
- Update nginx-gateway to version 1.30.1.
- Update bellsoft nginx to version 1.22.1-r5.
- Update bellsoft nginx to version 1.28.3-r2.
- Update canonical nginx to version 1.18.0-6ubuntu14.11.
- Update canonical nginx to version 1.24.0-2ubuntu7.8.
- Update alpine nginx to version 1.28.3-r1.
- Update alpine nginx to version 1.26.3-r00072.
- Update alpine rootio-nginx to version 1.26.3-r00072.
- Update debian nginx to version 1.30.0-3.
- Update nginx to version 1.26.3-r00073.
- Update rootio-nginx to version 1.26.3-r00073.
- Update nginx to version 1.20.2-r20072.
- Update rootio-nginx to version 1.20.2-r20072.
- Update nginx to version 1.26.3-r1.
- Update nginx to version 1.28.3-r1.
- Update nginx to version 1.30.1-r0.
- Update nginx to version 1.20.2-r20073.
- Update rootio-nginx to version 1.20.2-r20073.
- Update f5 nginx plus to version R36 P4 or later.
- Update f5 nginx open source to version 1.30.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | nginx |
< 1.18.0-6.1+deb11u6 Fix: upgrade to 1.18.0-6.1+deb11u6
|
| Debian:12 | debian | nginx |
< 1.22.1-9+deb12u7 Fix: upgrade to 1.22.1-9+deb12u7
|
| Debian:13 | debian | nginx |
< 1.26.3-3+deb13u5 Fix: upgrade to 1.26.3-3+deb13u5
|
| Ubuntu:25.10 | canonical | nginx |
< 1.28.0-6ubuntu1.3 Fix: upgrade to 1.28.0-6ubuntu1.3
|
| Ubuntu:26.04:LTS | canonical | nginx |
< 1.28.3-2ubuntu1.1 Fix: upgrade to 1.28.3-2ubuntu1.1
|
| Debian:14 | debian | nginx |
< 1.30.0-3 Fix: upgrade to 1.30.0-3
|
| Bitnami | – | nginx |
>= 0.6.27, < 1.30.1 Fix: upgrade to 1.30.1
|
| Bitnami | – | nginx-gateway |
>= 0.6.27, < 1.30.1 Fix: upgrade to 1.30.1
|
| Alpaquita:23 | bellsoft | nginx |
>= 1.22.1-r0, < 1.22.1-r5 Fix: upgrade to 1.22.1-r5
|
| Alpaquita:25 | bellsoft | nginx |
>= 1.28.0-r3, < 1.28.3-r2 Fix: upgrade to 1.28.3-r2
|
| Ubuntu:Pro:14.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | nginx | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | nginx | All versions |
| Ubuntu:22.04:LTS | canonical | nginx |
< 1.18.0-6ubuntu14.11 Fix: upgrade to 1.18.0-6ubuntu14.11
|
| Ubuntu:24.04:LTS | canonical | nginx |
< 1.24.0-2ubuntu7.8 Fix: upgrade to 1.24.0-2ubuntu7.8
|
| – | f5 | dos |
>= 4.3.0, <= 4.7.0 4.8.0 cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:* |
| – | f5 | nginx_gateway_fabric |
>= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.5.1 cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* |
| – | f5 | nginx_ingress_controller |
>= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.4.1 cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* |
| – | f5 | nginx_instance_manager |
>= 2.16.0, <= 2.21.1 cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:* |
| – | f5 | nginx_open_source |
>= 0.6.27, <= 1.30.0 cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* |
| – | f5 | nginx_plus |
>= r32, <= r36 cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* |
| – | f5 | waf |
>= 4.9.0, <= 4.16.0 >= 5.1.0, <= 5.8.0 >= 5.9.0, <= 5.12.1 cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:* |
| – | f5 | nginx plus | < R36 P4 |
| – | f5 | nginx open source | < 1.30.1 |
| Alpine:v3.22 | alpine | nginx |
< 1.28.3-r1 Fix: upgrade to 1.28.3-r1
|
| Alpine:v3.23 | alpine | nginx |
< 1.28.3-r1 Fix: upgrade to 1.28.3-r1
|
| Root:Alpine:3.20 | alpine | nginx |
< 1.26.3-r00072 Fix: upgrade to 1.26.3-r00072
|
| Root:Alpine:3.20 | alpine | rootio-nginx |
< 1.26.3-r00072 Fix: upgrade to 1.26.3-r00072
|
| Root:Alpine:3.20 | – | nginx |
< 1.26.3-r00073 Fix: upgrade to 1.26.3-r00073
|
| Root:Alpine:3.20 | – | rootio-nginx |
< 1.26.3-r00073 Fix: upgrade to 1.26.3-r00073
|
| Root:Alpine:3.15 | – | nginx |
< 1.20.2-r20072 < 1.20.2-r20073 Fix: upgrade to 1.20.2-r20072
|
| Root:Alpine:3.15 | – | rootio-nginx |
< 1.20.2-r20072 < 1.20.2-r20073 Fix: upgrade to 1.20.2-r20072
|
| Alpine:v3.21 | – | nginx |
< 1.26.3-r1 Fix: upgrade to 1.26.3-r1
|
| Alpine:v3.22 | – | nginx |
< 1.28.3-r1 Fix: upgrade to 1.28.3-r1
|
| Alpine:v3.24 | – | nginx |
< 1.30.1-r0 Fix: upgrade to 1.30.1-r0
|
Original advisory text
CVE-2026-42945 in nginx - Patched by Root
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
- https://security.alpinelinux.org/vuln/CVE-2026-42945 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42945 URL
- https://docs.bell-sw.com/security/cves/CVE-2026-42945 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-42945 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8271-1 Vendor Advisory
- https://nginx.org/en/security_advisories.html Third Party Advisory
- https://www.openwall.com/lists/oss-security/2026/05/13/7 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-42945 Third Party Advisory
- https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-ol... Third Party Advisory
- https://depthfirst.com/nginx-rift Mitigation Technical Description Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:17417
- https://access.redhat.com/errata/RHSA-2026:17751
- https://access.redhat.com/errata/RHSA-2026:17752
- https://access.redhat.com/errata/RHSA-2026:17753
- https://access.redhat.com/errata/RHSA-2026:17790
- https://access.redhat.com/errata/RHSA-2026:17791
- https://access.redhat.com/errata/RHSA-2026:17792
- https://access.redhat.com/errata/RHSA-2026:17793
- https://access.redhat.com/errata/RHSA-2026:19372
- https://access.redhat.com/errata/RHSA-2026:19374
- https://access.redhat.com/errata/RHSA-2026:20442
- https://access.redhat.com/errata/RHSA-2026:20444
- https://access.redhat.com/errata/RHSA-2026:21275
- https://access.redhat.com/errata/RHSA-2026:22382
- https://access.redhat.com/errata/RHSA-2026:22383
- https://access.redhat.com/errata/RHSA-2026:22394
- https://access.redhat.com/errata/RHSA-2026:22396
- https://access.redhat.com/errata/RHSA-2026:58981
- https://access.redhat.com/security/cve/CVE-2026-42945
- https://bugzilla.redhat.com/show_bug.cgi?id=2477116
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json
- https://my.f5.com/manage/s/article/K000161019 Mitigation Vendor Advisory
- https://github.com/DepthFirstDisclosures/Nginx-Rift Exploit Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-42945 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:17794
- https://access.redhat.com/errata/RHSA-2026:18029
- https://access.redhat.com/errata/RHSA-2026:18041
- https://access.redhat.com/errata/RHSA-2026:18063
- https://access.redhat.com/errata/RHSA-2026:19159
- https://access.redhat.com/errata/RHSA-2026:19371
- https://access.redhat.com/errata/RHSA-2026:22388
- https://access.redhat.com/errata/RHSA-2026:22389
- https://access.redhat.com/errata/RHSA-2026:22390
- https://access.redhat.com/errata/RHSA-2026:22393
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-122Heap-based Buffer Overflow
CWE-131Incorrect Calculation of Buffer Size
Timeline
Published13 May 2026
Updated9 Oct 2026
First seen13 May 2026
Sources
DEBIAN-CVE-2026-42945 · OSV
ALPINE-CVE-2026-42945 · OSV
BELL-CVE-2026-42945 · OSV
UBUNTU-CVE-2026-42945 · OSV
CVE-2026-42945 · NVD
BIT-nginx-2026-42945 · OSV
CVE-2026-42945 · MITRE
Track software like this
Free during beta