CVE-2026-42945

critical

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References

https://github.com/CynepMyx/nginx-rift-check

https://github.com/victorbanyas/nginx-cve-remediation

https://github.com/RyuRyu727975727975/snortrule_2026

https://github.com/azilRababe/CVE-2026-42945

https://github.com/limo57640-crypto/limo57640-crypto

https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945

https://github.com/jenniferreire26/CVE-2026-42945

https://github.com/y198nt/Nginx-chain-Rift-Poolslip

https://github.com/simota/nginx-rift-scanner

https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script

https://github.com/jaydarkseed757/rh-cve-pull

https://github.com/supamanluva/Celsius

https://github.com/edgecases-PurpleHax/cve-images

https://github.com/baranchen/ingress-nginx

https://github.com/niekaicheng/CVE-2026-42945_NGINX_Rift

https://github.com/bamov970/CVE-2026-42945-Nginx-RCE-bypass-ASLR

https://github.com/nu0l/NGINX-Rift

https://github.com/karakapaku43/CVE-2026-42945

https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945

https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc

https://github.com/SoWiEee/CVE-Research

https://github.com/yusufdalbudak/CVE-2026-42945

https://github.com/Unclecheng-li/poc-lab

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit

https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Scanner

https://github.com/fkj-src/fix_nginx_cve_2026_42945

https://github.com/hnytgl/cve-2026-42945

https://github.com/hnytgl/CVE-2026-42945

https://github.com/hershate/CVE-Lookup-skill

https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift

https://github.com/tal7aouy/nginx-cve-2026-42945

https://github.com/BarAppTeam/nginx-cve-fix

https://github.com/pinialt/echo-assignment

https://github.com/limo57640-crypto/nginx-rift-detector

https://github.com/sibersan/web-server-audit_CVE-2026-42945

https://github.com/dinosn/cve-2026-42945-nginx32-lab

https://github.com/barmi/cve-patch-auditor

https://github.com/pablinux87/nginx_check_CVE

https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab

https://github.com/jelasin/CVE-2026-42945

https://github.com/chenqin231/CVE-2026-42945

https://github.com/oseasfr/Scanner_CVE_2026-42945

https://github.com/0xBlackash/CVE-2026-42945

https://github.com/enclave-ai/nginx-rift-scanner

https://github.com/cipherspy/CVE-2026-42945-POC

https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC

https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

https://github.com/DepthFirstDisclosures/Nginx-Rift

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json

https://bugzilla.redhat.com/show_bug.cgi?id=2477116

https://access.redhat.com/security/cve/CVE-2026-42945

https://access.redhat.com/errata/RHSA-2026:58981

https://access.redhat.com/errata/RHSA-2026:22396

https://access.redhat.com/errata/RHSA-2026:22394

https://access.redhat.com/errata/RHSA-2026:22393

https://access.redhat.com/errata/RHSA-2026:22390

https://access.redhat.com/errata/RHSA-2026:22389

https://access.redhat.com/errata/RHSA-2026:22388

https://access.redhat.com/errata/RHSA-2026:22383

https://access.redhat.com/errata/RHSA-2026:22382

https://access.redhat.com/errata/RHSA-2026:21275

https://access.redhat.com/errata/RHSA-2026:20444

https://access.redhat.com/errata/RHSA-2026:20442

https://access.redhat.com/errata/RHSA-2026:19374

https://access.redhat.com/errata/RHSA-2026:19372

https://access.redhat.com/errata/RHSA-2026:19371

https://access.redhat.com/errata/RHSA-2026:19159

https://access.redhat.com/errata/RHSA-2026:18063

https://access.redhat.com/errata/RHSA-2026:18041

https://access.redhat.com/errata/RHSA-2026:18029

https://access.redhat.com/errata/RHSA-2026:17794

https://access.redhat.com/errata/RHSA-2026:17793

https://access.redhat.com/errata/RHSA-2026:17792

https://access.redhat.com/errata/RHSA-2026:17791

https://access.redhat.com/errata/RHSA-2026:17790

https://access.redhat.com/errata/RHSA-2026:17753

https://access.redhat.com/errata/RHSA-2026:17752

https://access.redhat.com/errata/RHSA-2026:17751

https://access.redhat.com/errata/RHSA-2026:17417

Details

Source: Mitre, NVD

Published: 2026-05-13

Updated: 2026-09-10

Named Vulnerability: RiftNamed Vulnerability: NGINX Rift

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 9.2

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.68047

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest