Critical NGINX Rewrite Module Buffer Overflow Vulnerability (CVE-2026-42945) (my.f5.com)
- CVE-2026-42945 critical buffer overflow in NGINX rewrite module
- Unauthenticated remote code execution or denial-of-service
- F5 advisory urges immediate patching
"F5 has issued advisory K000161019 detailing a critical heap-based buffer overflow in the NGINX ngx_http_rewrite_module, tracked as CVE-2026-42945. This vulnerability allows unauthenticated remote attackers to trigger a denial-of-service condition or potentially execute arbitrary code on affected systems. The rewrite module is commonly used for URL rewriting and redirection. F5 recommends immediate patching or mitigation via limiting access or disabling the module. This is a high-severity issue affecting many deployments of NGINX as a web server or reverse proxy. Users should check their version and apply updates from their vendor."
no comments yet.