18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
ID: 14da3d62-0ad9-5ddc-87d7-afaaeccfbf7c
STIX ID: report--14da3d62-0ad9-5ddc-87d7-afaaeccfbf7c
Feed Name: The Hacker News
Researchers disclosed multiple vulnerabilities affecting NGINX Plus and NGINX Open Source, including a critical heap buffer overflow (CVE-2026-42945, "NGINX Rift") reachable via crafted URIs that can cause heap corruption, worker crashes, or unauthenticated remote code execution (particularly where ASLR is disabled). The advisory lists affected versions across NGINX products, describes three additional flaws (CVE-2026-42946, CVE-2026-40701, CVE-2026-42934), and recommends applying patched releases or using configuration mitigations (e.g., replacing unnamed PCRE captures with named captures) if immediate updates are not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
