logo

NGINX Rift: CVE-2026-42945 Critical Heap Buffer Overflow Vulnerability Explained

ID: 3aeffafe-9f33-5025-86de-9325e73f54c7

STIX ID: report--3aeffafe-9f33-5025-86de-9325e73f54c7

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-07-22

Author: Huseyin Can YUCEEL

...
...

On May 13, 2026 researchers disclosed NGINX-Rift (CVE-2026-42945), a critical (CVSS 9.2) unauthenticated remote code execution vulnerability in NGINX's URL rewriting (ngx_http_rewrite_module) that affects widely deployed NGINX installations and several commercial products; the report details a reliable heap-buffer-overflow exploit chain that hijacks ngx_pool cleanup handlers to call system() and achieve RCE, lists related CVEs, provides configuration-based mitigation and monitoring advice, and recommends simulating attacks with the Picus platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.