18-year-old NGINX flaw raises DoS risk and possible RCE in certain configs

1 min read
Source: BleepingComputer
18-year-old NGINX flaw raises DoS risk and possible RCE in certain configs
Photo: BleepingComputer
TL;DR

An 18-year-old heap buffer overflow in NGINX's rewrite_module (CVE-2026-42945) can cause denial of service and, under specific rewrite configurations, unauthenticated remote code execution. Patches are available in NGINX Open Source 1.31.0 and 1.30.1 and related F5 products; real-world exploitability is debated, but the DoS risk makes patching or applying mitigations urgent, especially where ASLR is disabled to enable RCE in PoC tests.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer