CVE-2026-42945

critical

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json

https://bugzilla.redhat.com/show_bug.cgi?id=2477116

https://access.redhat.com/security/cve/CVE-2026-42945

https://access.redhat.com/errata/RHSA-2026:58981

https://access.redhat.com/errata/RHSA-2026:22396

https://access.redhat.com/errata/RHSA-2026:22394

https://access.redhat.com/errata/RHSA-2026:22393

https://access.redhat.com/errata/RHSA-2026:22390

https://access.redhat.com/errata/RHSA-2026:22389

https://access.redhat.com/errata/RHSA-2026:22388

https://access.redhat.com/errata/RHSA-2026:22383

https://access.redhat.com/errata/RHSA-2026:22382

https://access.redhat.com/errata/RHSA-2026:21275

https://access.redhat.com/errata/RHSA-2026:20444

https://access.redhat.com/errata/RHSA-2026:20442

https://access.redhat.com/errata/RHSA-2026:19374

https://access.redhat.com/errata/RHSA-2026:19372

https://access.redhat.com/errata/RHSA-2026:19371

https://access.redhat.com/errata/RHSA-2026:19159

https://access.redhat.com/errata/RHSA-2026:18063

https://access.redhat.com/errata/RHSA-2026:18041

https://access.redhat.com/errata/RHSA-2026:18029

https://access.redhat.com/errata/RHSA-2026:17794

https://access.redhat.com/errata/RHSA-2026:17793

https://access.redhat.com/errata/RHSA-2026:17792

https://access.redhat.com/errata/RHSA-2026:17791

https://access.redhat.com/errata/RHSA-2026:17790

https://access.redhat.com/errata/RHSA-2026:17753

https://access.redhat.com/errata/RHSA-2026:17752

https://access.redhat.com/errata/RHSA-2026:17751

https://access.redhat.com/errata/RHSA-2026:17417

Details

Source: Mitre, NVD

Published: 2026-05-13

Updated: 2026-08-25

Named Vulnerability: RiftNamed Vulnerability: NGINX Rift

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 9.2

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.68047

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest