Summary
CVE-2026-42945 is a critical heap-based buffer overflow vulnerability in the NGINX ngx_http_rewrite_module that occurs when rewrite directives containing a query string are used with rewrite, if, or set directives referencing unnamed PCRE capture groups such as $1 or $2. An unauthenticated attacker can exploit the flaw through crafted HTTP requests, potentially causing NGINX worker crashes and denial-of-service conditions. In environments where ASLR is disabled or bypassed, the vulnerability may also enable remote code execution. The issue affects NGINX Open Source versions 0.6.27–1.30.0, and NGINX Plus releases R32-R36, and is fixed in NGINX Open Source 1.30.1/1.31.0 and NGINX Plus R36 P4, R35 P2, and R32 P6.
Urgent Actions Required
- Upgrade NGINX Open Source to version 1.30.1, 1.31.0, or a later fixed release.
- Upgrade NGINX Plus to a supported fixed version, including R36 P4, R35 P2, R32 P6, or later releases containing the fix.
- Review NGINX configurations for rewrite rules that use unnamed capture groups, such as $1 or $2, together with query-string-based rewrite directives.
- Replace unnamed capture groups with named captures where applicable to eliminate the vulnerable code path.
- Ensure ASLR is enabled on affected systems to reduce the likelihood of successful code execution.
- Monitor NGINX instances for unexpected worker process restarts, crashes, or repeated availability issues that may indicate exploitation attempts.
Which Systems Are Vulnerable to CVE-2026-42945?
Technical Overview
- Vulnerability Type: Heap-Based Buffer Overflow (CWE-122)
-
Affected Software/Versions:
NGINX Open Source- Versions 0.6.27 - 1.30.0
- Releases R32 - R36
-
CVSS Vector: v3.1
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Patch Availability: Yes, available
How Does the CVE-2026-42945 Exploit Work?
The attack typically follows these steps:
What Causes CVE-2026-42945?
Vulnerability Root Cause:
This vulnerability is caused by a flaw in the NGINX ngx_http_rewrite_module script engine. When a rewrite directive containing a query string is used with subsequent rewrite, if, or set directives that reference unnamed PCRE capture groups (such as $1 or $2), the module incorrectly calculates the required buffer size during request processing. This mismatch can lead to a heap-based buffer overflow in the NGINX worker process, resulting in worker crashes and, under certain conditions, remote code execution.
How Can You Mitigate CVE-2026-42945?
If immediate patching is delayed or not possible:
- Review NGINX configurations for rewrite directives that use unnamed capture groups such as $1 or $2.
- Replace unnamed captures with named captures in affected rewrite rules.
- Ensure Address Space Layout Randomization (ASLR) is enabled on the operating system.
- Restrict access to affected services using firewall rules or access control lists where feasible.
- Monitor NGINX logs and worker processes for unexpected crashes, restarts, or abnormal activity that may indicate exploitation attempts.
Which Assets and Systems Are at Risk?
-
Asset Types Affected:
- NGINX Open Source Deployments - Versions 0.6.27 through 1.30.0 using vulnerable rewrite configurations
- NGINX Plus Deployments - Releases R32 through R36 affected by the flaw in the ngx_http_rewrite_module
- Web Servers and Reverse Proxies - Systems processing HTTP requests through vulnerable rewrite rules that use unnamed PCRE capture groups
-
Business-Critical Systems at Risk:
- Internet-Facing Web Services - Applications relying on affected NGINX instances to handle incoming traffic
- Production Web Infrastructure - Environments where worker process crashes could disrupt service availability
- NGINX-Based Platforms - Deployments using vulnerable rewrite directives that process user-supplied requests
-
Exposure Level:
- Externally Accessible NGINX Servers - Particularly those using the affected rewrite configuration pattern
- Systems with ASLR Disabled - Higher risk environments where successful exploitation could lead to remote code execution
- Unpatched NGINX Installations - Open Source and Plus deployments running affected versions without vendor fixes applied
Will Patching CVE-2026-42945 Cause Downtime?
Patch application impact: Low. Upgrading to a fixed NGINX version typically requires a service restart or redeployment, resulting in minimal downtime.
Mitigation (if immediate patching is not possible): Replace unnamed capture groups ($1, $2) with named captures and ensure ASLR is enabled. This reduces risk but does not fully remediate the vulnerability.
How Can You Detect CVE-2026-42945 Exploitation?
Exploitation Signatures:
Look for crafted HTTP requests targeting NGINX servers that use vulnerable rewrite configurations with unnamed capture groups ($1, $2) and query string handling.
Indicators of Compromise (IOCs/IOAs):
- Repeated crashes or restarts of NGINX worker processes
- Unexpected HTTP 502 or 504 errors associated with specific requests
- Requests containing URI characters that require escaping (such as &, spaces, or +) targeting vulnerable rewrite rules
Behavioral Indicators:
- Frequent worker process respawns
- Service instability or degraded application performance
- Repeated requests triggering the same rewrite path before the worker crashes
Alerting Strategy:
-
Priority: Critical
- Alert on repeated NGINX worker crashes or restarts
- Alert on spikes in HTTP 502 and 504 responses
- Monitor for suspicious requests targeting vulnerable rewrite configurations
Remediation & Response
-
Remediation Timeline:
- Immediate: Upgrade to a fixed NGINX release where possible.
- If patching is delayed, replace unnamed capture groups ($1, $2) with named captures and ensure ASLR is enabled.
- Verify vulnerable NGINX versions and configurations have been removed after remediation.
-
Incident Response Considerations:
- Investigate unexpected NGINX worker crashes or restart loops.
- Review logs for repeated requests targeting vulnerable rewrite rules.
- Monitor for HTTP 502 and 504 errors that may indicate exploitation attempts.
- After remediation, continue monitoring for abnormal requests targeting affected rewrite configurations.
See What Deep Session Inspection Detects Beyond Traditional DPI
-
-
- Understand the gap between DPI and DSI
- Detect hidden threats and data leaks
- Gain deeper visibility into network, email, and web traffic
- Improve threat detection with context-rich analysis
-
CVSS Breakdown Table
| Metric | Value | Description |
|---|---|---|
| Base Score | 8.1 | High-severity vulnerability with potential for denial of service and remote code execution under specific conditions |
| Attack Vector | Network | Can be triggered through crafted HTTP requests sent remotely |
| Attack Complexity | High | Exploitation requires a specific NGINX configuration and additional conditions |
| Privileges Required | None | No authentication is required |
| User Interaction | None | No user action is needed for exploitation |
| Scope | Unchanged | Impact is limited to the affected NGINX component |
| Confidentiality Impact | High | Successful code execution could expose sensitive information |
| Integrity Impact | High | An attacker may be able to execute arbitrary code and alter system behavior |
| Availability Impact | High | Exploitation can crash NGINX worker processes and disrupt services |
References: