NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
https://latesthackingnews.com/2026/06/19/nginx-http-3-vulnerability-aslr-analysis/
https://hackread.com/hackers-exploit-nginx-rift-vulnerability-nginx-f5-products/
https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html
https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-03
https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html
https://www.securityweek.com/f5-patches-over-50-vulnerabilities/
https://thehackernews.com/2026/05/18-year-old-nginx-rewrite-module-flaw.html
https://github.com/CynepMyx/nginx-rift-check
https://github.com/victorbanyas/nginx-cve-remediation
https://github.com/RyuRyu727975727975/snortrule_2026
https://github.com/azilRababe/CVE-2026-42945
https://github.com/limo57640-crypto/limo57640-crypto
https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945
https://github.com/jenniferreire26/CVE-2026-42945
https://github.com/y198nt/Nginx-chain-Rift-Poolslip
https://github.com/simota/nginx-rift-scanner
https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script
https://github.com/jaydarkseed757/rh-cve-pull
https://github.com/supamanluva/Celsius
https://github.com/edgecases-PurpleHax/cve-images
https://github.com/baranchen/ingress-nginx
https://github.com/niekaicheng/CVE-2026-42945_NGINX_Rift
https://github.com/bamov970/CVE-2026-42945-Nginx-RCE-bypass-ASLR
https://github.com/nu0l/NGINX-Rift
https://github.com/karakapaku43/CVE-2026-42945
https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945
https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc
https://github.com/SoWiEee/CVE-Research
https://github.com/yusufdalbudak/CVE-2026-42945
https://github.com/Unclecheng-li/poc-lab
https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit
https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Scanner
https://github.com/fkj-src/fix_nginx_cve_2026_42945
https://github.com/hnytgl/cve-2026-42945
https://github.com/hnytgl/CVE-2026-42945
https://github.com/hershate/CVE-Lookup-skill
https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift
https://github.com/tal7aouy/nginx-cve-2026-42945
https://github.com/BarAppTeam/nginx-cve-fix
https://github.com/pinialt/echo-assignment
https://github.com/limo57640-crypto/nginx-rift-detector
https://github.com/sibersan/web-server-audit_CVE-2026-42945
https://github.com/dinosn/cve-2026-42945-nginx32-lab
https://github.com/barmi/cve-patch-auditor
https://github.com/pablinux87/nginx_check_CVE
https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab
https://github.com/jelasin/CVE-2026-42945
https://github.com/chenqin231/CVE-2026-42945
https://github.com/oseasfr/Scanner_CVE_2026-42945
https://github.com/0xBlackash/CVE-2026-42945
https://github.com/enclave-ai/nginx-rift-scanner
https://github.com/cipherspy/CVE-2026-42945-POC
https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC
https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945
https://github.com/DepthFirstDisclosures/Nginx-Rift
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json
https://bugzilla.redhat.com/show_bug.cgi?id=2477116
https://access.redhat.com/security/cve/CVE-2026-42945
https://access.redhat.com/errata/RHSA-2026:58981
https://access.redhat.com/errata/RHSA-2026:22396
https://access.redhat.com/errata/RHSA-2026:22394
https://access.redhat.com/errata/RHSA-2026:22393
https://access.redhat.com/errata/RHSA-2026:22390
https://access.redhat.com/errata/RHSA-2026:22389
https://access.redhat.com/errata/RHSA-2026:22388
https://access.redhat.com/errata/RHSA-2026:22383
https://access.redhat.com/errata/RHSA-2026:22382
https://access.redhat.com/errata/RHSA-2026:21275
https://access.redhat.com/errata/RHSA-2026:20444
https://access.redhat.com/errata/RHSA-2026:20442
https://access.redhat.com/errata/RHSA-2026:19374
https://access.redhat.com/errata/RHSA-2026:19372
https://access.redhat.com/errata/RHSA-2026:19371
https://access.redhat.com/errata/RHSA-2026:19159
https://access.redhat.com/errata/RHSA-2026:18063
https://access.redhat.com/errata/RHSA-2026:18041
https://access.redhat.com/errata/RHSA-2026:18029
https://access.redhat.com/errata/RHSA-2026:17794
https://access.redhat.com/errata/RHSA-2026:17793
https://access.redhat.com/errata/RHSA-2026:17792
https://access.redhat.com/errata/RHSA-2026:17791
https://access.redhat.com/errata/RHSA-2026:17790
https://access.redhat.com/errata/RHSA-2026:17753
https://access.redhat.com/errata/RHSA-2026:17752
Published: 2026-05-13
Updated: 2026-09-10
Named Vulnerability: RiftNamed Vulnerability: NGINX Rift
Base Score: 9
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C
Severity: High
Base Score: 8.1
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 9.2
Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.68047
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest