---
id: CVE-2026-42945
title: "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\_module"
summary: "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module\_module. This vulnerability exists when the rewrite\_directive is followed by a rewrite, if, or set\_directive and an unnamed Perl-Compatible Regular Expre…"
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
  - CWE-131
vendor: f5
product: dos
affected:
  - 'dos >= 4.3.0, <= 4.7.0'
  - dos = 4.8.0
  - 'nginx_gateway_fabric >= 1.3.0, <= 1.6.2'
  - 'nginx_gateway_fabric >= 2.0.0, <= 2.5.1'
  - 'nginx_ingress_controller >= 3.5.0, <= 3.7.2'
  - 'nginx_ingress_controller >= 4.0.0, <= 4.0.1'
  - 'nginx_ingress_controller >= 5.0.0, <= 5.4.1'
  - 'nginx_instance_manager >= 2.16.0, <= 2.21.1'
  - 'nginx_open_source >= 0.6.27, <= 1.30.0'
  - 'nginx_plus >= r32, <= r36'
  - 'waf >= 4.9.0, <= 4.16.0'
  - 'waf >= 5.1.0, <= 5.8.0'
  - 'waf >= 5.9.0, <= 5.12.1'
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_e4s_v_9_0
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - codeready_linux_builder_eus_v_9_4
  - codeready_linux_builder_eus_v_9_6
  - enterprise_linux_codeready_linux_builder_v_9
  - hardened_images
  - openshift_data_foundation 4.14
  - openshift_data_foundation 4.15
  - openshift_data_foundation 4.16
  - openshift_data_foundation 4.17
  - openshift_data_foundation 4.18
  - openshift_data_foundation 4.19
  - openshift_data_foundation 4.20
  - openshift_data_foundation 4.21
  - satellite 6.18
  - satellite 6.19
  - update_infrastructure 5
published: '2026-05-13'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:20:09.723'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945'
references:
  - url: 'https://my.f5.com/manage/s/article/K000161019'
    label: f5sirt@f5.com
  - url: 'https://depthfirst.com/nginx-rift'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/DepthFirstDisclosures/Nginx-Rift'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:17417'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17751'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17752'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17753'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17790'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17791'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17792'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17793'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17794'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18029'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18041'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:18063'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19159'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19371'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19372'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19374'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:20442'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:20444'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22382'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22383'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22388'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22389'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22390'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22393'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22394'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22396'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42945'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2477116'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42945'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42945'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-13T00:00:00+00:00'
epss: 0.68047
epssPercentile: 0.99292
exploits:
  github: 44
  githubRepos:
    - 'https://github.com/cipherspy/CVE-2026-42945-POC'
    - 'https://github.com/friparia/NGINX_RIFT_SCAN_CVE_2026_42945'
    - 'https://github.com/MateusVerass/nGixshell'
  checkedAt: '2026-09-23T07:14:04.934Z'
exploitAvailable: true
ingestedAt: '2026-09-07T14:12:12.910Z'
---

## Overview

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

## Affected

- `dos >= 4.3.0, <= 4.7.0`
- `dos = 4.8.0`
- `nginx_gateway_fabric >= 1.3.0, <= 1.6.2`
- `nginx_gateway_fabric >= 2.0.0, <= 2.5.1`
- `nginx_ingress_controller >= 3.5.0, <= 3.7.2`
- `nginx_ingress_controller >= 4.0.0, <= 4.0.1`
- `nginx_ingress_controller >= 5.0.0, <= 5.4.1`
- `nginx_instance_manager >= 2.16.0, <= 2.21.1`
- `nginx_open_source >= 0.6.27, <= 1.30.0`
- `nginx_plus >= r32, <= r36`
- `waf >= 4.9.0, <= 4.16.0`
- `waf >= 5.1.0, <= 5.8.0`
- `waf >= 5.9.0, <= 5.12.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:17790** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17790)
- **RHSA-2026:18063** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18063)
- **RHSA-2026:19159** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19159)
- **RHSA-2026:18041** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:18041)
- **RHSA-2026:17791** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.0) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17791)
- **RHSA-2026:17751** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17751)
- **RHSA-2026:17792** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.4), Red Hat CodeReady Linux Builder EUS (v.9.4) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17792)
- **RHSA-2026:17793** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.4) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17793)
- **RHSA-2026:17752** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17752)
- **RHSA-2026:17794** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17794)
- **RHSA-2026:17753** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-05-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:17753)
- **Red Hat VEX** · Critical · affected: Red Hat Lightspeed proxy 1 · no fix planned: Red Hat Lightspeed proxy 1 · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json)
