18-year-old NGINX vulnerability allows DoS, potential RCE
ID: dac87697-c42f-51b1-9e49-dff38ed81958
STIX ID: report--dac87697-c42f-51b1-9e49-dff38ed81958
Feed Name: Bleeping Computer
An 18-year-old heap buffer overflow (CVE-2026-42945) in NGINX's rewrite module and three other memory-corruption flaws were discovered; the primary issue has a CVSS 9.2 rating and can cause reliable denial-of-service and, under specific conditions (ASLR disabled and particular rewrite/set configurations), remote code execution. Affected NGINX Open Source and various F5/Nginx product builds are listed; fixes and mitigations (updates and replacing unnamed PCRE capture groups) are available from F5/NGINX.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
