CVE-2026-42945: Critical NGINX Heap Buffer Overflow Vulnerability (imperva.com)
0xBASE INTEL BRIEF
- Critical 18-year-old vulnerability in NGINX.
- Allows DoS and potential RCE via heap overflow.
- Patch available; immediate update urged.
"CVE-2026-42945 (dubbed 'NGINX Rift') is a critical heap buffer overflow in NGINX's ngx_http_rewrite_module present for 18 years. Unauthenticated attackers can cause denial-of-service or potentially remote code execution via crafted HTTP requests. A patch is available."
no comments yet.