18-year-old NGINX flaw raises DoS risk and possible RCE in certain configs

1 min read
Source: BleepingComputer
18-year-old NGINX flaw raises DoS risk and possible RCE in certain configs
Photo: BleepingComputer
TL;DR Summary

An 18-year-old heap buffer overflow in NGINX's rewrite_module (CVE-2026-42945) can cause denial of service and, under specific rewrite configurations, unauthenticated remote code execution. Patches are available in NGINX Open Source 1.31.0 and 1.30.1 and related F5 products; real-world exploitability is debated, but the DoS risk makes patching or applying mitigations urgent, especially where ASLR is disabled to enable RCE in PoC tests.

Share this article

Reading Insights

Total Reads

0

Unique Readers

12

Time Saved

5 min

vs 6 min read

Condensed

95%

1,15762 words

Want the full story? Read the original article

Read on BleepingComputer