logo

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

ID: 14da3d62-0ad9-5ddc-87d7-afaaeccfbf7c

STIX ID: report--14da3d62-0ad9-5ddc-87d7-afaaeccfbf7c

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed multiple vulnerabilities affecting NGINX Plus and NGINX Open Source, including a critical heap buffer overflow (CVE-2026-42945, "NGINX Rift") reachable via crafted URIs that can cause heap corruption, worker crashes, or unauthenticated remote code execution (particularly where ASLR is disabled). The advisory lists affected versions across NGINX products, describes three additional flaws (CVE-2026-42946, CVE-2026-40701, CVE-2026-42934), and recommends applying patched releases or using configuration mitigations (e.g., replacing unnamed PCRE captures with named captures) if immediate updates are not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.