logo

F5 nginx vulnerability: Find impacted systems

ID: 4f42d8a8-669c-5c2a-a201-5a284cabee0b

STIX ID: report--4f42d8a8-669c-5c2a-a201-5a284cabee0b

Feed Name: runZero Blog

Threat Score
70/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: runZero Team

...
...

A security advisory discloses CVE-2026-42945, a heap-based buffer overflow in NGINX's ngx_http_rewrite_module rated High (CVSS 8.1). Numerous NGINX and F5 product versions are affected; an unauthenticated remote attacker could trigger worker process restarts (DoS) and, in environments without ASLR, possibly achieve arbitrary code execution. The advisory provides fixed versions to upgrade to and a mitigation (use named capture groups in rewrite rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.