CVE-2026-42945High· 8.1▾ MidnightPoC availableNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 13.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
68%
44 GitHub repos
Last analysed / modified upstream
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
dos >= 4.3.0, <= 4.7.0dos = 4.8.0nginx_gateway_fabric >= 1.3.0, <= 1.6.2nginx_gateway_fabric >= 2.0.0, <= 2.5.1nginx_ingress_controller >= 3.5.0, <= 3.7.2nginx_ingress_controller >= 4.0.0, <= 4.0.1nginx_ingress_controller >= 5.0.0, <= 5.4.1nginx_instance_manager >= 2.16.0, <= 2.21.1nginx_open_source >= 0.6.27, <= 1.30.0nginx_plus >= r32, <= r36waf >= 4.9.0, <= 4.16.0waf >= 5.1.0, <= 5.8.0waf >= 5.9.0, <= 5.12.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42055High· 8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules
CVE-2026-2050High· 7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2025-64031Low· 2.5libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9
CVE-2026-16118High· 7.1A flaw was found in xdgmime
CVE-2026-34743Medium· 5.3XZ Utils provide a general-purpose data-compression library plus command-line tools
CVE-2026-42536High· 7.5Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…