logo

CVE-2026-42945: Imperva Customers Protected Against Critical NGINX Rewrite Module Vulnerability

ID: 6832bf5b-973b-5ece-b4f3-ddebeb69bef6

STIX ID: report--6832bf5b-973b-5ece-b4f3-ddebeb69bef6

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Gabi Sharadin

...
...

Researchers disclosed CVE-2026-42945 (NGINX Rift), a critical heap-based buffer overflow in the ngx_http_rewrite_module affecting NGINX Open Source 0.6.27–1.30.0 and NGINX Plus R32–R36; specially crafted HTTP requests that abuse unnamed PCRE capture groups and replacement strings can trigger heap corruption leading to worker crashes, application-layer denial-of-service, and potential remote code execution. Patched releases (NGINX 1.30.1, 1.31.0+, NGINX Plus R32 P6, R36 P4) are available, and organizations are urged to patch and review rewrite rules; Imperva reports protections for its Cloud and On-Prem WAF customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.