CVE detail
CVE-2026-42945
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 10.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
46 source links · newest first
- Hitachi Energy e-mesh EMSCISA Alerts
ors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-42945 NGINX Plus and NGINX Open Source used in e-mesh EMS have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an
governmentwww.cisa.govJul 7, 2026, 12:00 PM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack Why pure extortion is […]
newssecurityaffairs.comMay 24, 2026, 11:51 AM- Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploitedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. Earbud sensors can authenticate users by their heartbeat, study finds Researchers built a continuous authentication … More →
newswww.helpnetsecurity.comMay 24, 2026, 8:00 AM - 18th May – Threat Intelligence ReportCheck Point Research
ss sandbox controls, expose restricted files, leak secrets, and gain owner-level access. The flaws include the critical CVE-2026-44112, rated CVSS 9.6. Researchers developed an AI-assisted macOS kernel exploit that bypasses Apple’s Memory Integrity Enforcement on M5 chips and grants full system control on macOS 26.4.1. Anthropic’s Mythos Preview report
vendorresearch.checkpoint.comMay 18, 2026, 2:58 PM A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday. The vulnerability, dubbed NGINX Rift, can be reliably exploited to trigger a denial-of-service condition and can potentially allow for unauthenticated remote code execution, all achievable by sending a specially crafted HTTP request to a vulnerable NGINX instance. What is NGINX? NGINX is the most widely deployed web server and, as such, it’s one of … More →
newswww.helpnetsecurity.comMay 18, 2026, 1:29 PMThe flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
newswww.securityweek.comMay 18, 2026, 7:27 AMA critical NGINX flaw (CVE-2026-42945) is actively exploited, allowing crashes or possible code execution via malicious HTTP requests. A critical vulnerability in NGINX Plus and NGINX Open, tracked as CVE-2026-42945 (CVSS v4 score of 9.2), is already being actively exploited shortly after disclosure. “We’re seeing active exploitation of CVE-2026-42945 in F5 NGINX, a heap buffer […]
newssecurityaffairs.comMay 18, 2026, 6:33 AMIntroduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
newswww.securityweek.comMay 16, 2026, 10:02 AMInformation published.
vendormsrc.microsoft.comMay 16, 2026, 8:05 AMResearchers have found a critical vulnerability in the widely used Nginx web server that can potentially lead to remote code execution under certain conditions. The flaw is a heap buffer overflow that has gone undetected in the program’s code for the past 18 years. Tracked as CVE-2026-42945, the vulnerability is one of 4 bugs found […]
newswww.csoonline.comMay 14, 2026, 11:06 PM- NGINX Rift: an 18-year-old flaw in the world’s most deployed web server just came to lightSecurity Affairs
Researchers found a critical 18-year-old buffer overflow flaw in NGINX, tracked as CVE-2026-42945 and named NGINX Rift. If you run NGINX, and statistically speaking, there is a very good chance you do, this week brought news worth stopping for. Security researchers at depthfirst disclosed a critical heap buffer overflow vulnerability in both NGINX Plus and […]
newssecurityaffairs.comMay 14, 2026, 1:30 PM - F5 Patches Over 50 VulnerabilitiesSecurityWeek
The company’s latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX.
newswww.securityweek.comMay 14, 2026, 10:47 AM Linked URL: https://github.com/DepthFirstDisclosures/Nginx-Rift | Posted by 882542F3884314B | 5 points | 0 comments
communitynews.ycombinator.comMay 13, 2026, 7:28 PM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 13, 2026, 4:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2477116bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/security/cve/CVE-2026-42945access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22396access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22394access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22393access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22390access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22389access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22388access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22383access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:22382access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:21275access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:20444access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:20442access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:19374access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:19372access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:19371access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:19159access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:18063access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:18041access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:18029access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17794access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17793access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17792access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17791access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17790access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17753access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17752access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17751access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM - https://access.redhat.com/errata/RHSA-2026:17417access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 13, 2026, 4:16 PM No excerpt available.
Exploitgithub.comMay 13, 2026, 4:16 PM- https://depthfirst.com/nginx-riftdepthfirst.com
No excerpt available.
Exploitdepthfirst.comMay 13, 2026, 4:16 PM No excerpt available.
Vendor Advisorymy.f5.comMay 13, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.99 · max 1 stars
- F2u0a0d3/CVE-2026-42945-nginx-rift-pocHigh confidencegithubDiscovery source unavailable1 starsDiscovered Jul 9, 2026, 5:43 AM
- DepthFirstDisclosures/Nginx-RiftHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 14, 2026, 12:21 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42055CVSS 9.2 · Critical
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2…
- CVE-2026-48142CVSS 6.3 · Medium
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset ut…
- CVE-2026-42946CVSS 8.3 · High
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsg…
- CVE-2026-42934CVSS 6.3 · Medium
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering (…
- CVE-2026-40701CVSS 6.3 · Medium
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directi…
- CVE-2026-40460CVSS 6.9 · Medium
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or…