CVE-2026-42945Active Exploitation(f5 / dos)

CRITICALCVSS 9.2 · CRITICAL

Exploitation observed; activity peaked at 83 mentions and remains active

Immediate actions

  • Patch f5 dos systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

9.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-131

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dos
  • nginx_gateway_fabric
  • nginx_ingress_controller
  • nginx_instance_manager

Threat summary

  • Active exploitation appears in 167 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 464 mentions across 52 observed days

What's happening

  • Active exploitation reported across 167 signals
  • Exploit tool or code specified in 46 signals
  • PoC mentioned or linked in 115 signals
  • Patch or workaround mentioned in 167 signals
  • Technical details provided in 335 signals
  • Disclosure: 95 classified signals
  • Peaked 50d ago at 83 mentions (2026-05-14); latest day: 1
  • 464 total mentions across 52 days

Affected systems

Vendors
Products
dosnginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_pluswaf

1 version affected across 7 products

Deep dive

Activity timeline464 mentions / 52d
021426283Mentions · 2026-05-13: 14Mentions · 2026-05-14: 83Mentions · 2026-05-15: 43Mentions · 2026-05-16: 16Mentions · 2026-05-17: 58Mentions · 2026-05-18: 68Mentions · 2026-05-19: 40Mentions · 2026-05-20: 21Mentions · 2026-05-21: 17Mentions · 2026-05-22: 9Mentions · 2026-05-23: 7Mentions · 2026-05-24: 3Mentions · 2026-05-25: 6Mentions · 2026-05-26: 4Mentions · 2026-05-27: 4Mentions · 2026-05-28: 1Mentions · 2026-05-29: 4Mentions · 2026-05-30: 3Mentions · 2026-05-31: 5Mentions · 2026-06-02: 1Mentions · 2026-06-04: 3Mentions · 2026-06-05: 1Mentions · 2026-06-06: 1Mentions · 2026-06-07: 14Mentions · 2026-06-08: 2Mentions · 2026-06-09: 3Mentions · 2026-06-12: 2Mentions · 2026-06-13: 1Mentions · 2026-06-14: 2Mentions · 2026-06-16: 2Mentions · 2026-06-17: 1Mentions · 2026-06-18: 1Mentions · 2026-06-19: 1Mentions · 2026-06-23: 2Mentions · 2026-06-25: 1Mentions · 2026-07-01: 1Mentions · 2026-07-04: 1Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Mentions · 2026-07-18: 1Mentions · 2026-07-19: 1Mentions · 2026-07-22: 1Mentions · 2026-07-30: 1Mentions · 2026-08-03: 2Mentions · 2026-08-04: 3Mentions · 2026-08-21: 1Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Mentions · 2026-08-31: 1Mentions · 2026-09-13: 1Mentions · 2026-09-21: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-05-13: 4PoC Mentioned / Linked · 2026-05-14: 28PoC Mentioned / Linked · 2026-05-15: 14PoC Mentioned / Linked · 2026-05-16: 8PoC Mentioned / Linked · 2026-05-17: 11PoC Mentioned / Linked · 2026-05-18: 7PoC Mentioned / Linked · 2026-05-19: 6PoC Mentioned / Linked · 2026-05-20: 4PoC Mentioned / Linked · 2026-05-21: 5PoC Mentioned / Linked · 2026-05-22: 3PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-29: 2PoC Mentioned / Linked · 2026-06-05: 1PoC Mentioned / Linked · 2026-06-07: 6PoC Mentioned / Linked · 2026-06-12: 2PoC Mentioned / Linked · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-23: 1PoC Mentioned / Linked · 2026-07-01: 1PoC Mentioned / Linked · 2026-07-18: 1PoC Mentioned / Linked · 2026-07-22: 1PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-31: 1PoC Mentioned / Linked · 2026-09-21: 1Exploit Tool / Code · 2026-05-13: 2Exploit Tool / Code · 2026-05-14: 15Exploit Tool / Code · 2026-05-15: 8Exploit Tool / Code · 2026-05-16: 4Exploit Tool / Code · 2026-05-17: 2Exploit Tool / Code · 2026-05-18: 4Exploit Tool / Code · 2026-05-19: 3Exploit Tool / Code · 2026-05-20: 1Exploit Tool / Code · 2026-05-22: 2Exploit Tool / Code · 2026-05-25: 1Exploit Tool / Code · 2026-05-29: 1Exploit Tool / Code · 2026-06-07: 1Exploit Tool / Code · 2026-07-22: 1Exploit Tool / Code · 2026-09-21: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-05-14: 5Active Exploitation · 2026-05-15: 5Active Exploitation · 2026-05-17: 33Active Exploitation · 2026-05-18: 49Active Exploitation · 2026-05-19: 28Active Exploitation · 2026-05-20: 12Active Exploitation · 2026-05-21: 3Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-23: 2Active Exploitation · 2026-05-24: 2Active Exploitation · 2026-05-25: 4Active Exploitation · 2026-05-26: 2Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-05-30: 1Active Exploitation · 2026-05-31: 3Active Exploitation · 2026-06-02: 1Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-06-07: 4Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-07-01: 1Active Exploitation · 2026-07-08: 1Active Exploitation · 2026-07-19: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-04: 2Active Exploitation · 2026-08-31: 1Active Exploitation · 2026-09-13: 1Patch / Workaround · 2026-05-13: 6Patch / Workaround · 2026-05-14: 41Patch / Workaround · 2026-05-15: 17Patch / Workaround · 2026-05-16: 4Patch / Workaround · 2026-05-17: 14Patch / Workaround · 2026-05-18: 22Patch / Workaround · 2026-05-19: 21Patch / Workaround · 2026-05-20: 7Patch / Workaround · 2026-05-21: 8Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-23: 5Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-27: 2Patch / Workaround · 2026-05-29: 2Patch / Workaround · 2026-06-04: 3Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-09: 3Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-09-21: 1Technical Details · 2026-05-13: 13Technical Details · 2026-05-14: 67Technical Details · 2026-05-15: 33Technical Details · 2026-05-16: 10Technical Details · 2026-05-17: 49Technical Details · 2026-05-18: 41Technical Details · 2026-05-19: 24Technical Details · 2026-05-20: 17Technical Details · 2026-05-21: 13Technical Details · 2026-05-22: 6Technical Details · 2026-05-23: 6Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 6Technical Details · 2026-05-26: 3Technical Details · 2026-05-27: 2Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 3Technical Details · 2026-05-30: 1Technical Details · 2026-05-31: 2Technical Details · 2026-06-02: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-07: 11Technical Details · 2026-06-08: 1Technical Details · 2026-06-09: 2Technical Details · 2026-06-14: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-25: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-19: 1Technical Details · 2026-07-22: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-03: 2Technical Details · 2026-08-04: 3Technical Details · 2026-08-21: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-13: 1Technical Details · 2026-09-21: 105-1305-1805-2305-2806-0406-0906-1707-0107-1908-2109-2109-30
Signal classification7 categories
Active Exploitation
16034.6%
Disclosure
9520.5%
Patch
7516.2%
PoC
5812.5%
General
5612.1%
Exploit
163.5%
Referenced assets221 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-1314
Active Exploitation1Disclosure6General1Patch3PoC3
2026-05-1483
Active Exploitation5Disclosure27Exploit6False Positive1General10Patch23PoC11
2026-05-1543
Active Exploitation4Disclosure14Exploit3False Positive1General3Patch12PoC6
2026-05-1616
Disclosure4General4Patch3PoC5
2026-05-1758
Active Exploitation33Disclosure10General5Patch3PoC7
2026-05-1868
Active Exploitation49Disclosure6Exploit1General2Patch8PoC2
2026-05-1940
Active Exploitation24Disclosure4Exploit2General2Patch6PoC2
2026-05-2021
Active Exploitation12General4Patch3PoC2
2026-05-2117
Active Exploitation3Disclosure5General3Patch2PoC4
2026-05-229
Active Exploitation1Disclosure3General1Patch1PoC3
2026-05-237
Active Exploitation1Disclosure3General1Patch2
2026-05-243
Active Exploitation2General1
2026-05-256
Active Exploitation4Disclosure1Exploit1
2026-05-264
Active Exploitation2Disclosure2
2026-05-274
Disclosure1General1Patch2
2026-05-281
Disclosure1
2026-05-294
Active Exploitation1Exploit1Patch1PoC1
2026-05-303
Active Exploitation1General2
2026-05-315
Active Exploitation3Disclosure1General1
2026-06-021
Active Exploitation1
2026-06-043
Active Exploitation1General1Patch1
2026-06-051
PoC1
2026-06-061
General1
2026-06-0714
Active Exploitation4Disclosure4Exploit1General1PoC4
2026-06-082
General1Patch1
2026-06-093
Active Exploitation1Patch2
2026-06-122
General1PoC1
2026-06-131
General1
2026-06-142
General1PoC1
2026-06-162
Disclosure1Patch1
2026-06-171
Patch1
2026-06-181
General1
2026-06-191
General1
2026-06-232
False Positive1General1
2026-06-251
Disclosure1
2026-07-011
Active Exploitation1
2026-07-041
General1
2026-07-071
General1
2026-07-081
Active Exploitation1
2026-07-181
PoC1
2026-07-191
General1
2026-07-221
Exploit1
2026-07-301
General1
2026-08-032
Active Exploitation1General1
2026-08-043
Active Exploitation2Disclosure1
2026-08-211
PoC1
2026-08-251
PoC1
2026-08-261
PoC1
2026-08-311
Active Exploitation1
2026-09-131
Active Exploitation1
2026-09-211
PoC1
Full discourse20 posts
  • Zhenpeng (Leo) Lin@Markak_
    Disclosure

    NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at https://depthfirst.com/nginx-rift

    Post summary

    Researchers uncovered an eighteen‑year‑old heap overflow in NGINX that affects many releases; they recommend upgrading or reconfiguring to mitigate the vulnerability.

    23290331.1K625208.8K
    3.5K followersView on X
  • Het Mehta@hetmehtaa
    PoC

    Every 3rd website you visit runs Nginx. 18,959,833 of them can be hijacked right now. A bug from 2008 just got a working exploit. CVE-2026-42945 (CVSS 9.2) No login. No access. Just one HTTP request. → Heap overflow → Worker process → RCE Patch ASAP to Nginx 1.31.0 or 1.30.1 PoC is already out: https://github.com/DepthFirstDisclosures/Nginx-Rift

    Post summary

    A heap‑overflow RCE in Nginx (CVE‑2026‑42945) has a publicly available Proof‑of‑Concept on GitHub; affected users should apply the recommended patch immediately.

    3212322810677152.7K
    42.2K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Exploit

    FULL REMOTE CODE EXECUTION on default nginx 1.30.0 no config changes needed. 🫠 Verichains a deadly exploit chain combining Nginx-Rift (CVE-2026-42945) + Nginx-PoolSlip (CVE-2026-9256). 2-byte heap pointer overwrite & heap over-read then ASLR bypass to arbitrary command execution via system() on connection teardown.

    Post summary

    The post details a full remote code execution chain on default nginx 1.30.0 using CVE-2026-42945 and CVE-2026-9256, outlining heap pointer overwrite, ASLR bypass, and system() execution without needing configuration changes.

    51174884617118.8K
    49.9K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 NGINX bug (CVE-2026-42945) now under active exploitation. Critical heap overflow in rewrite module. Attackers can crash workers with one request (possible RCE). Patch now if using NGINX ≤1.30.0. Check rewrite/if/set rules. Full details: https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html

    Post summary

    The post highlights that CVE‑2026‑42945 is being actively exploited with a severe heap overflow in the NGINX rewrite module. A patch applies to versions ≤1.30.0, and further details can be found in the linked article.

    1721123800385277.5K
    1.9M followersView on X
  • yousukezan@yousukezan
    Patch

    F5は13日、NGINX に深刻な脆弱性「CVE-2026-42945」が存在すると公表した。細工されたURIを送信するだけで、認証不要でヒープベースのバッファオーバーフローを引き起こせる。CVSS v4スコアは9.2で、リモートコード実行につながる恐れがある。 影響を受けるのは、NGINX Open Source 0.6.27〜1.30.0のほか、NGINX Plus、Ingress Controller、WAF製品群など広範囲に及ぶ。脆弱性は18年以上前から存在していたとされる。問題はHTTPリクエスト処理を担う ngx_http_rewrite_module にあり、特定の rewrite 設定で、正規表現キャプチャと「?」を含む置換文字列を組み合わせた場合に発生する。 攻撃者は単一のHTTPリクエストでワーカープロセスをクラッシュさせたり、任意コードを実行できる可能性があり、リバースプロキシやロードバランサとしてNGINXを利用する多数のサービスに影響する恐れがある。F5は修正版としてNGINX 1.31.0および1.30.1などを公開し、速やかなアップデートを呼びかけている。 https://depthfirst.com/nginx-rift

    Post summary

    NGINX is vulnerable to CVE‑2026‑42945, a heap‑based buffer overflow that can lead to remote code execution. F5 has released patched versions (NGINX 1.31.0/1.30.1) and urged users to update promptly.

    122724547294137.4K
    14.5K followersView on X
  • yousukezan@yousukezan
    Disclosure

    世界的に広く使われるWebサーバー「NGINX」で新たな重大脆弱性が公開された。細工したHTTPリクエストだけでサービス停止や任意コード実行に至る恐れがある。 問題は「nginx-poolslip」と呼ばれるCVE-2026-9256で、NGINX Open SourceとNGINX Plusの双方に影響する。原因はngx_http_rewrite_module内のメモリ処理不備で、特定のrewrite正規表現とPCREキャプチャ組み合わせを使う設定で発生する。攻撃者は認証不要で悪意あるHTTPリクエストを送信し、NGINXワーカープロセス内でヒープバッファオーバーフローを引き起こせる。 NGINXは各リクエストごとに専用メモリプールを使用しており、その内部にはクリーンアップ処理用リンクリストが存在する。今回の脆弱性では、攻撃者が隣接構造体へポインタを“滑らせる”形で破壊でき、クリーンアップ時の制御フロー乗っ取りにつながる可能性がある。 これは先日公開された「NGINX Rift」(CVE-2026-42945)と同じngx_http_rewrite_moduleに関連しており、前回パッチが根本的なメモリプール問題を修正できていなかったことも判明した。 最小でもワーカープロセスがクラッシュしDoS状態となるが、ASLR無効環境や回避可能な環境では任意コード実行も成立し得る。CVSSはv3.1で8.1、v4.0では9.2評価となっている。 影響を受けるのはNGINX Open Source 1.30.1以前および1.31.0で、1.30.2または1.31.1への更新が必要。NGINX Plus利用者にはR36 P5、R32 P7、R37.0.1.1への更新が推奨されている。 https://cybersecuritynews.com/nginx-poolslip-vulnerability/

    Post summary

    The post announces CVE-2026-9256, detailing the technical exploitation vector, impact, affected NGINX versions, and required patches, but no PoC or active exploitation evidence is provided.

    02131653624350.8K
    14.5K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Public PoC for NGINX CVE-2026-42945. An 18-year-old RCE flaw in the rewrite module enables server takeover. Update to NGINX 1.31.0 or 1.30.1 immediately. #NGINX #CyberSecurity #InfoSec #RCE #Vulnerability #CVE #WebServer #PoC #GitHub #SysAdmin #TechNews https://securityonline.info/nginx-rce-vulnerability-cve-2026-42945-poc-disclosure/ https://t.co/gp7VGBbdDL

    Post summary

    A public Proof of Concept for CVE-2026-42945 is disclosed, highlighting an 18‑year‑old RCE flaw in NGINX’s rewrite module, and users are urged to upgrade to version 1.31.0 or 1.30.1 for remediation.

    787740522949.4K
    12.5K followersView on X
  • Hamid Kashfi@hkashfi
    PoC

    Here's the PoC for Nginx CVE-2026-42945 which works against vanilla Ubuntu (and any other distro?) + Nginx with ASLR enabled. I have included all iterations of the PoC the LLM was kicked to improve. TL;DR: We can use an LFI/file-read primitive to leak enough details from /proc/<nginx-worker>/mem to bypass ASLR and achieve reliable RCE, in most cases at first shot. There are still other ways to make it work, with even less subtle primitives. If you ask Geppetto nicely, he will help you ;) https://github.com/Hamid-K/nginx-rift-private-lab

    Post summary

    A functional PoC demonstrating a local file‑read leading to ASLR bypass and remote code execution on Ubuntu Nginx is released, with the code available on GitHub.

    592533628840.4K
    10.5K followersView on X
  • divyansh tiwari@DivyanshT91162
    Patch

    The internet runs on Nginx. And right now, millions of servers are one request away from getting owned. A 17-year-old bug just turned into a full-blown RCE exploit: → CVE-2026-42945 (CVSS 9.2) → No auth → No credentials → Just a single malicious HTTP request Attack chain: Heap Overflow → Nginx Worker Hijack → Remote Code Execution Researchers estimate ~19 MILLION exposed instances. PoC is already public. If you're running Nginx, patch NOW to 1.31.0 or 1.30.1 before bots start mass-scanning the internet.

    Post summary

    A new high‑severity Nginx RCE (CVE‑2026‑42945) has a public PoC and is affecting ~19 million servers; the advisory urges immediate patching to version 1.31.0 or 1.30.1.

    1060332826855.8K
    9.6K followersView on X
  • The Hacker News@TheHackersNews
    PoC

    🚨 NGINX Rift CVE-2026-42945 PoC upgraded — full ASLR bypass now public. New chain: heap overflow + same-host LFI / arbitrary file read → leaks runtime state from /proc/<worker>/mem, derives heap targets + system() address on the fly. No hardcoded addresses. No ASLR disable. Unauthenticated RCE on rewrite + set directive setups. Patch now: • OSS: 1.30.1 / 1.31.0 • Plus: R36 P4, R35 P2, R32 P6

    Post summary

    The post announces a public PoC for CVE-2026-42945, detailing an ASLR bypass by exploiting a heap overflow and LFI, and lists available patches for affected NGINX releases.

    98810336182123.1K
    1.9M followersView on X
  • hayapi🧶@yo_hayasaka
    Disclosure

    読んだ。 Nginxのこの脆弱性を悪用すれば、リモートでCopy Failを刺せちゃうじゃんね --- CVE-2026-42945 · Heap-based Buffer Overflow · CVSS v4.0 9.2 (Critical) https://depthfirst.com/nginx-rift

    Post summary

    The post announces a new critical Nginx Heap‑based Buffer Overflow (CVE‑2026‑42945), noting its remote exploitation potential, but it does not provide a PoC, exploit code, or patch information.

    293329917433.3K
    1.9K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-42945: RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX's ngx_http_rewrite_module introduced in 2008 GitHub: https://github.com/depthfirstdisclosures/nginx-rift https://t.co/XhQv80TJyf

    Post summary

    A proof‑of‑concept for CVE‑2026‑42945, a critical heap buffer overflow in NGINX, is released on GitHub, but no active exploitation or patch details are mentioned.

    268232016636.8K
    223.7K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚡ An 18-year-old flaw in NGINX can let unauthenticated attackers run code or crash servers using crafted HTTP requests. Tracked as CVE-2026-42945 and named NGINX Rift, the bug affects NGINX Plus and Open Source. Patch details and mitigation steps: https://thehackernews.com/2026/05/18-year-old-nginx-rewrite-module-flaw.html

    Post summary

    NGINX CVE‑2026‑42945, named NGINX Rift, enables unauthenticated remote code execution or server crashes via crafted HTTP requests, and patch and mitigation steps have been released.

    98132567595.8K
    1.9M followersView on X
  • Modat@modat_magnify
    Active Exploitation

    CVE-2026-42945  ⚠️ NGINX – Heap Overflow / Possible RCE Actively Exploited in the Wild (CVSS 9.2)  A heap-based buffer overflow in ngx_http_rewrite_module affects NGINX Open Source and NGINX Plus ≤1.30.0. Crafted HTTP requests can trigger worker crashes and potentially lead to remote code execution on systems with ASLR disabled.  The flaw requires specific rewrite/if/set directives using unnamed PCRE captures ($1, $2) with replacement strings containing “?”. The vulnerability is actively being exploited in the wild.  Mitigation: Patch immediately to Nginx 1.31.0 or 1.30.1.  Modat Magnify Query:  technology="Nginx"  The platform:  https://magnify.modat.io/  #threatintel #vulnerability #CVE202642945 #NGINX #RCE #DoS #infosec #Critical #ModatMagnify

    Post summary

    NGINX’s ngx_http_rewrite_module has a heap overflow (CVE‑2026‑42945) that is actively exploited for potential RCE; users should patch to 1.31.0/1.30.1 immediately.

    33621978229.2K
    1.7K followersView on X
  • Clandestine@akaclandestine
    General

    GitHub - friparia/NGINX_RIFT_SCAN_CVE_2026_42945: Scan Nginx Rift (CVE-2026-42945) · GitHub https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945

    Post summary

    The text references a GitHub project that scans for CVE-2026-42945, but provides no concrete PoC, exploit code, or patch details.

    2270111838.8K
    62.5K followersView on X
  • Het Mehta@hetmehtaa
    Patch

    Can’t patch Nginx right now? Here’s your stopgap. CVE-2026-42945 triggers through unnamed regex captures in rewrite rules. Change this:  rewrite ^/user/([0-9]+)$ /profile?id=$1;  To this:  rewrite ^/user/(?&lt;id&gt;[0-9]+)$ /profile?id=$id;  Not a fix. A workaround.

    Post summary

    The post supplies a temporary workaround for CVE‑2026‑42945 by adjusting Nginx rewrite rules, offering a mitigative measure rather than a full patch.

    21921227318.6K
    42.2K followersView on X
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-42945: A Critical Heap Buffer Overflow in NGINX. 🧐Credit by depthfirst:https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability 📊 868M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Nginx%22 👇Query HUNTER : http://product.name="Nginx" 📰Refer:https://github.com/DepthFirstDisclosures/Nginx-Rift https://thehackernews.com/2026/05/18-year-old-nginx-rewrite-module-flaw.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces CVE‑2026‑42945, a critical heap buffer overflow in NGINX, and points to research pages and a GitHub repo that contain a PoC and exploit details, but it does not mention active exploitation or a patch.

    0221995710.8K
    26.0K followersView on X
  • Cristian Borghello@SeguInfo
    Active Exploitation

    Ya se observa explotación activa de la vulnerabilidad CVE-2026-42945 (CVSS 9.2) en Nginx #nginxrift Se recomienda aplicar las actualizaciones a Nginx y F5 de inmediato. https://blog.segu-info.com.ar/2026/05/nginx-rift-vulnerabilidad-critica-en.html

    Post summary

    The post reports active exploitation of CVE-2026-42945 in Nginx, urges immediate updates to Nginx and F5, and notes a CVSS score of 9.2.

    1260101469.4K
    38.3K followersView on X
  • Simi@coder_simran
    Exploit

    Every 3rd website you visit runs Nginx. 18,959,833 of them can be hijacked right now. A bug from 2008 just got a working exploit. CVE-2026-42945 (CVSS 9.2) No login. No access. Just one HTTP request. → Heap overflow → Worker process → RCE Patch ASAP to Nginx 1.31.0 or 1.30.1

    Post summary

    CVE‑2026‑42945 is a heap‑overflow RCE in Nginx with a working exploit now available; patches to Nginx 1.31.0 or 1.30.1 are urgently needed.

    140806126.8K
    1.3K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Nginxにおける重大(Critical)な18年物の脆弱性がPoC(攻撃の概念実証コード)付きで開示された。CVE-2026-42945はCVSSスコア9.2の遠隔コード実行。確定で刺せるヒープベースのバッファオーバーフロー。ngx_http_rewrite_moduleで無名PCREキャプチャを使用していることが条件。 https://securityonline.info/nginx-rce-vulnerability-cve-2026-42945-poc-disclosure/

    Post summary

    A critical 2018 Nginx heap‑based buffer overflow (CVE‑2026‑42945) has been disclosed with a PoC and code link, highlighting remote code execution (CVSS 9.2), yet no patch or active exploitation has been reported.

    122152286.7K
    7.6K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appf5dos-nginx-
Appf5dos4.8.0nginx-
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5waf-nginx-

Explore more