Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryactively-exploited-vulnerabilityinternet-facing-service-vulnerabilityproof-of-concept-release

NGINX Rift Rewrite Flaw Triggers Worker Crashes and Possible RCE

Updated 3d agoFirst seen May 13, 202631 sources

F5 and NGINX disclosed CVE-2026-42945 ("NGINX Rift"), a critical heap buffer overflow in ngx_http_rewrite_module affecting NGINX Open Source 0.6.27 through 1.30.0 and NGINX Plus R32 through R36. The bug is exposed when servers use a specific rewrite pattern: a rewrite directive with unnamed PCRE captures such as $1 or $2, a replacement string containing ?, and a following rewrite, if, or set directive. An unauthenticated attacker can send crafted HTTP requests to corrupt heap memory in the worker process, reliably causing crashes and restarts; code execution is considered possible in weaker environments, particularly where ASLR is disabled. Fixes were released in NGINX 1.30.1, 1.31.0, and patched NGINX Plus builds, while Debian, AlmaLinux, and other downstream vendors began shipping updates.

Public writeups and proof-of-concept code quickly drove attacker interest, and multiple reports said VulnCheck observed exploitation attempts on canary systems within days of disclosure. Researchers and defenders broadly agreed that denial-of-service is the most practical near-term impact, while widespread reliable RCE is less likely on hardened systems with modern memory protections enabled. Administrators were urged to patch internet-facing reverse proxies, load balancers, ingress controllers, and API gateways, audit rewrite rules for unnamed captures, and use named captures as a temporary mitigation where upgrades cannot be applied immediately. The same release cycle also addressed additional NGINX flaws including CVE-2026-42946, CVE-2026-40701, and CVE-2026-42934.

Share:
NGINX Rift Rewrite Flaw Triggers Worker Crashes and Possible RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 9, 20264d ago

HPE Aruba Networking issued advisory on CVE-2026-42945 status

HPE published product advisory HPESBNW05064 rev.1 addressing the status of the NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945 in HPE Aruba Networking products. This represents a new vendor-specific downstream response for affected product lines.

HPESBNW05064 rev.1 - Status of NGINX ngx_http_rewrite_module Vulnerability (CVE-2026-42945) in HPE Aruba Networking Products
May 18, 202626d ago

Reports warned of active exploitation in the wild

Security outlets reported that CVE-2026-42945 was being actively exploited in the wild, citing VulnCheck observations and rapid attacker scanning of exposed NGINX servers. Coverage emphasized that denial-of-service exploitation was realistic, while broad reliable RCE remained less practical because exploitation depends on specific rewrite configurations and often disabled ASLR.

Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945
May 16, 202628d ago

VulnCheck observed exploitation attempts against CVE-2026-42945

VulnCheck reported seeing exploitation activity against CVE-2026-42945 on its canary systems shortly after disclosure. One report explicitly states exploitation attempts began on May 16, indicating attackers moved quickly after patches and PoC details became public.

Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) - Help Net Security

Debian issued DSA-6278-1 nginx security update

Debian published security advisory DSA-6278-1 for nginx, indicating distribution-level remediation for the disclosed vulnerabilities. The advisory marks a downstream packaging response following the upstream disclosure and fixes.

[SECURITY] [DSA 6278-1] nginx security update
May 13, 20261mo ago

AlmaLinux released backported nginx fixes to its repositories

AlmaLinux reproduced the denial-of-service condition for CVE-2026-42945 across AlmaLinux 8, 9, 10, and Kitten 10, then released backported patched nginx packages to testing repositories, with Kitten 10 receiving the fix in its regular repository. The vendor also recommended replacing unnamed captures with named captures as a temporary mitigation.

AlmaLinux OS - Forever-Free Enterprise-Grade Operating System

DepthFirst published root-cause analysis and PoC for NGINX Rift

DepthFirst published technical analysis and a proof of concept for CVE-2026-42945, describing how the rewrite engine's handling of question marks and unnamed captures can lead to heap corruption. Reports said the PoC demonstrated worker-process RCE in a lab setup with ASLR disabled.

CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC : r/netsec

Public disclosure of CVE-2026-42945 and companion NGINX flaws

CVE-2026-42945 was publicly disclosed as a critical heap buffer overflow in ngx_http_rewrite_module affecting NGINX Open Source and NGINX Plus, alongside additional CVEs in SCGI/UWSGI, SSL, and charset components. Public advisories described the vulnerable rewrite pattern, affected versions, and the risk of worker crashes and possible code execution when ASLR is disabled.

oss-sec: NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945
May 1, 20261mo ago

NGINX 1.31.0 and 1.30.1 released with CVE-2026-42945 fixes

The nginx project released version 1.31.0 and the stable branch update 1.30.1, including fixes for CVE-2026-42945 and several other security issues. The release notes highlighted the rewrite-module flaw and other vulnerabilities across proxy, SCGI/UWSGI, charset, HTTP/3, and OCSP-related components.

���������� nginx 1.31.0 � ����������� RCE-����������, ��������������� ����� HTTP-������
Apr 21, 20262mo ago

F5/NGINX patched CVE-2026-42945 after responsible disclosure

F5 and NGINX released fixes for CVE-2026-42945 after responsible disclosure, covering affected NGINX Open Source and NGINX Plus versions. Multiple reports state patches were issued on April 21, 2026, with upgrade guidance and configuration workarounds provided.

NGINX Rift: an 18-year-old flaw in the world's most deployed web server just came to light
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

51 LINKEDOpen in app
Affected products
17 linked
Nginx PlusNginx Open SourceNginx Ingress ControllerF5 Waf For NginxNginx Instance ManagerNginx App Protect WafNginx Gateway FabricNginxNginx App Protect DosNginxF5osBig-IpRed Hat Enterprise LinuxF5 Distributed CloudChromeNginx Open SourceNginx Plus
Organizations
28 linked
F5depthfirstVulnCheckCensysAlmalinuxCanonicalSecurity AffairsRed HatNginxAlmaLinux OS FoundationBlackpoint CyberSOCRadarBlack DuckDryRun SecuritySuseMeta PlatformsNSFOCUSBeazley SecurityMicrosoft CorporationGitHubOracleHuntressDebianGoogleSecure.comCIQF5 NGINXDepthFirst AI
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.