NGINX Web Server: Vulnerability Allows DoS and Potential Code Execution (heise.de)
0xBASE INTEL BRIEF
- CVE-2026-9256 patched in NGINX Open Source and NGINX Plus
- Flaw in ngx_http_rewrite_module enables DoS and potential code execution
- No known active exploitation; advisories released
"A high-severity vulnerability (CVE-2026-9256) has been patched in NGINX Open Source and NGINX Plus. The flaw in the ngx_http_rewrite_module can cause memory corruption, leading to denial-of-service or potentially arbitrary code execution. No active exploitation has been reported. Affected versions: NGINX Open Source 1.30.2, 1.31.1; NGINX Plus 37.0.11, R32 P7, R36 P5."
#NGINX vulnerability
#CVE-2026-9256
#DoS and remote code execution
no comments yet.