CVE-2026-42945
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVSS v4.0
- 9.2 CRITICAL
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 68.05% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2026-05-13
- Updated
- 2026-08-25
Proof-of-concept exploits (26)
- cipherspy/CVE-2026-42945-POC61★ · 2026-05-14
- p3Nt3st3r-sTAr/CVE-2026-42945-POC15★ · 2026-05-14
- rheodev/CVE-2026-4294523★ · 2026-05-14
- nanwinata/nginxrift-CVE-2026-429452★ · 2026-05-15
- ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-429450★ · 2026-05-14
- 0xBlackash/CVE-2026-429452★ · 2026-05-14
- jelasin/CVE-2026-429454★ · 2026-05-15
- tal7aouy/nginx-cve-2026-429452★ · 2026-05-17
- quantumworld-dpdns-io/CVE-2026-429450★ · 2026-05-28
- imSre9/CVE-2026-429450★ · 2026-05-19
- hnytgl/CVE-2026-429451★ · 2026-06-06
- aratane/CVE-2026-429451★ · 2026-07-01
- yusufdalbudak/CVE-2026-429450★ · 2026-05-20
- RedCrazyGhost/CVE-2026-429451★ · 2026-05-19
- hulina9900-boop/DIY-CVE-2026-42945-POC0★ · 2026-06-17
- forxiucn/nginx-cve-2026-42945-poc1★ · 2026-05-15
- josephfelix/CVE-2026-42945-nginx-rift1★ · 2026-05-25
- Renison-Gohel/CVE-2026-42945-NGINX-Rift1★ · 2026-05-17
- webdev75950-ux/nginx-rce-cve-2026-429450★ · 2026-05-23
- F2u0a0d3/CVE-2026-42945-nginx-rift-poc1★ · 2026-05-22
- sec-sys/CVE-2026-42945-Reverse-Shell-POC0★ · 2026-06-14
- laohuang101/NginxRift-Poc0★ · 2026-07-20
- FranklinF25/cve-2026-429450★ · 2026-08-30
- Kentox493/CVE-2026-42945_NginxRift
- LiaoZiqi-GZFLS/CVE-2026-42945
- leojaguaribe/cve-zerolab