TGViewer
CatOps CatOps @catops · 5.08K subscribers
Post #2905 1.55K
Continuing with security advisory.

NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945.

~
NGINX Plus and NGINX Open Source have a vulnerability in the *ngx_http_rewrite_module* module. This vulnerability exists when the *rewrite* directive is followed by a *rewrite*, *if*, or *set* directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. (CVE-2026-42945)


Don't confuse the F5's NGINX Ingress Controller with the community-led ingress-nginx, that is deprecated now.

In any case, though, if you're using the ngx_http_rewrite_module (and it's widely used!), you are likely vulnerable.


#security
F5 NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945 Security Advisory Description NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the "rewrite" directive with a query string is followed (in the same location) by the "if" or "set" directive…
More from @catops
  1. Sep 29, 2026A Cybersecurity books bundle by O’Reilly on Humble Bundle. The bundle is fresh and is stil…
  2. Sep 28, 2026​​For today’s Donations Monday, I’d like to remind you about a fundraiser for a pickup tru…
  3. Sep 26, 2026Here’s Datadog’s take on the increased load on CI. In this article they explain how their…
  4. Sep 25, 2026A new chapter of the CatOps Digest is here! https://newsletter.catops.dev/p/catops-digest-…
  5. Sep 24, 2026Shopify wrote an article on them moving from React Native to the native code for their mob…
  6. Sep 23, 2026A bunch of practice exams on Humble Bundle, if you're into this type of thing. This offer…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →