Critical 18-Year-Old NGINX RCE (CVE-2026-42945) and GitHub PoC Disclosed
ID: 7c2e169d-d1ba-5e65-bc62-34d80f7fea8b
STIX ID: report--7c2e169d-d1ba-5e65-bc62-34d80f7fea8b
Feed Name: securityonline.info
Threat Score
NGINX disclosure: CVE-2026-42945 (CVSS 9.2) is a deterministic heap buffer overflow in the ngx_http_rewrite_module that can be triggered by common rewrite patterns using unnamed PCRE captures and question marks, enabling unauthenticated RCE; proof-of-concept exploit code is public and multiple NGINX Open Source, NGINX Plus, and ancillary products are affected — immediate upgrades and replacing unnamed captures with named captures are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
