F5 and NGINX disclosed CVE-2026-42945 ("NGINX Rift"), a critical heap buffer overflow in ngx_http_rewrite_module affecting NGINX Open Source 0.6.27 through 1.30.0 and NGINX Plus R32 through R36. The bug is exposed when servers use a specific rewrite pattern: a rewrite directive with unnamed PCRE captures such as $1 or $2, a replacement string containing ?, and a following rewrite, if, or set directive. An unauthenticated attacker can send crafted HTTP requests to corrupt heap memory in the worker process, reliably causing crashes and restarts; code execution is considered possible in weaker environments, particularly where ASLR is disabled. Fixes were released in NGINX 1.30.1, 1.31.0, and patched NGINX Plus builds, while Debian, AlmaLinux, and other downstream vendors began shipping updates.
Public writeups and proof-of-concept code quickly drove attacker interest, and multiple reports said VulnCheck observed exploitation attempts on canary systems within days of disclosure. Researchers and defenders broadly agreed that denial-of-service is the most practical near-term impact, while widespread reliable RCE is less likely on hardened systems with modern memory protections enabled. Administrators were urged to patch internet-facing reverse proxies, load balancers, ingress controllers, and API gateways, audit rewrite rules for unnamed captures, and use named captures as a temporary mitigation where upgrades cannot be applied immediately. The same release cycle also addressed additional NGINX flaws including CVE-2026-42946, CVE-2026-40701, and CVE-2026-42934.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
HPE published product advisory HPESBNW05064 rev.1 addressing the status of the NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945 in HPE Aruba Networking products. This represents a new vendor-specific downstream response for affected product lines.
Security outlets reported that CVE-2026-42945 was being actively exploited in the wild, citing VulnCheck observations and rapid attacker scanning of exposed NGINX servers. Coverage emphasized that denial-of-service exploitation was realistic, while broad reliable RCE remained less practical because exploitation depends on specific rewrite configurations and often disabled ASLR.
VulnCheck reported seeing exploitation activity against CVE-2026-42945 on its canary systems shortly after disclosure. One report explicitly states exploitation attempts began on May 16, indicating attackers moved quickly after patches and PoC details became public.
Debian published security advisory DSA-6278-1 for nginx, indicating distribution-level remediation for the disclosed vulnerabilities. The advisory marks a downstream packaging response following the upstream disclosure and fixes.
AlmaLinux reproduced the denial-of-service condition for CVE-2026-42945 across AlmaLinux 8, 9, 10, and Kitten 10, then released backported patched nginx packages to testing repositories, with Kitten 10 receiving the fix in its regular repository. The vendor also recommended replacing unnamed captures with named captures as a temporary mitigation.
DepthFirst published technical analysis and a proof of concept for CVE-2026-42945, describing how the rewrite engine's handling of question marks and unnamed captures can lead to heap corruption. Reports said the PoC demonstrated worker-process RCE in a lab setup with ASLR disabled.
CVE-2026-42945 was publicly disclosed as a critical heap buffer overflow in ngx_http_rewrite_module affecting NGINX Open Source and NGINX Plus, alongside additional CVEs in SCGI/UWSGI, SSL, and charset components. Public advisories described the vulnerable rewrite pattern, affected versions, and the risk of worker crashes and possible code execution when ASLR is disabled.
The nginx project released version 1.31.0 and the stable branch update 1.30.1, including fixes for CVE-2026-42945 and several other security issues. The release notes highlighted the rewrite-module flaw and other vulnerabilities across proxy, SCGI/UWSGI, charset, HTTP/3, and OCSP-related components.
F5 and NGINX released fixes for CVE-2026-42945 after responsible disclosure, covering affected NGINX Open Source and NGINX Plus versions. Multiple reports state patches were issued on April 21, 2026, with upgrade guidance and configuration workarounds provided.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
31 references tracked. Mallory keeps watching after this page renders.
support.hpe.com
Open sourcesecurityonline.info
Open sourcethecyberexpress.com
Open sourcescworld.com
Open sourcedepthfirst.com
Open sourcebugflation.com
Open sourceopennet.me
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.