logo

NGINX Rift: an 18-year-old flaw in the world’s most deployed web server just came to light

ID: e0324459-1b8b-5091-810f-aec8f07f3109

STIX ID: report--e0324459-1b8b-5091-810f-aec8f07f3109

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Pierluigi Paganini

...
...

Researchers disclosed a critical 18‑year‑old heap buffer overflow in NGINX (CVE-2026-42945, "NGINX Rift") that can enable unauthenticated remote code execution by sending a specially crafted HTTP request when certain rewrite directive patterns (unnamed PCRE captures with question-mark replacements) are present; the flaw affects many NGINX Open Source and NGINX Plus releases and related F5/NGINX products, patches and configuration workarounds were released on April 21, 2026, and three additional NGINX vulnerabilities were published alongside the Rift advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.