<Vulnerability name="CVE-2026-42945">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Critical</ThreatSeverity>
    <PublicDate>2026-05-13T14:12:43</PublicDate>
    <Bugzilla id="2477116" url="https://bugzilla.redhat.com/show_bug.cgi?id=2477116" xml:lang="en:us">
nginx: NGINX: Arbitrary Code Execution Vulnerability
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-131</CWE>
    <Details xml:lang="en:us" source="Mitre">
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests under specific rewrite configurations. This can lead to a heap buffer overflow in the NGINX worker process, which may result in arbitrary code execution if Address Space Layout Randomization (ASLR), a security technique to prevent exploitation, is disabled. Otherwise, this flaw causes a denial of service due to a restart of the NGINX worker process.
    </Details>
    <Statement xml:lang="en:us">
Critical: This flaw in NGINX's ngx_http_rewrite_module can lead to arbitrary code execution due to a heap buffer overflow if Address Space Layout Randomization (ASLR) is disabled, or a denial of service otherwise. Exploitation requires specific, non-default NGINX rewrite configurations involving unnamed PCRE captures and a question mark in the replacement string.
    </Statement>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.1">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-05-18T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:18063">RHSA-2026:18063</Advisory>
        <Package name="nginx">nginx-2:1.26.3-2.el10_1.2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-05-19T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19159">RHSA-2026:19159</Advisory>
        <Package name="nginx">nginx-2:1.26.3-6.el10_2.3</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17790">RHSA-2026:17790</Advisory>
        <Package name="nginx">nginx-2:1.26.3-1.el10_0.9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-05-18T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:18041">RHSA-2026:18041</Advisory>
        <Package name="nginx:1.24">nginx:1.24-8100020260514165201.489197e6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-18T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:18029">RHSA-2026:18029</Advisory>
        <Package name="nginx">nginx-2:1.20.1-24.el9_7.3</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-19T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19371">RHSA-2026:19371</Advisory>
        <Package name="nginx:1.24">nginx:1.24-9080020260514160836.9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-19T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19372">RHSA-2026:19372</Advisory>
        <Package name="nginx:1.26">nginx:1.26-9080020260514152324.9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-05-19T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:19374">RHSA-2026:19374</Advisory>
        <Package name="nginx">nginx-2:1.20.1-28.el9_8.2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.0">
        <ProductName>Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17791">RHSA-2026:17791</Advisory>
        <Package name="nginx">nginx-1:1.20.1-10.el9_0.4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.2">
        <ProductName>Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17751">RHSA-2026:17751</Advisory>
        <Package name="nginx">nginx-1:1.20.1-14.el9_2.6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17792">RHSA-2026:17792</Advisory>
        <Package name="nginx">nginx-1:1.20.1-16.el9_4.6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17793">RHSA-2026:17793</Advisory>
        <Package name="nginx:1.24">nginx:1.24-9040020260514192210.9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17752">RHSA-2026:17752</Advisory>
        <Package name="nginx:1.24">nginx:1.24-9060020260514175739.9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17753">RHSA-2026:17753</Advisory>
        <Package name="nginx:1.26">nginx:1.26-9060020260514170123.9</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-05-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17794">RHSA-2026:17794</Advisory>
        <Package name="nginx">nginx-2:1.20.1-22.el9_6.6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-05-14T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17417">RHSA-2026:17417</Advisory>
        <Package name="nginx-main">nginx-main-1.30.1-1.hum1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:satellite:6.18::el9">
        <ProductName>Red Hat Satellite 6.18</ProductName>
        <ReleaseDate>2026-05-25T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20442">RHSA-2026:20442</Advisory>
        <Package name="satellite/iop-gateway-rhel9">satellite/iop-gateway-rhel9:1779706745</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:satellite:6.19::el9">
        <ProductName>Red Hat Satellite 6.19</ProductName>
        <ReleaseDate>2026-05-25T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:20444">RHSA-2026:20444</Advisory>
        <Package name="satellite/iop-gateway-rhel9">satellite/iop-gateway-rhel9:1779706797</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21275">RHSA-2026:21275</Advisory>
        <Package name="rhui5/cds-rhel9">rhui5/cds-rhel9:1779798159</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-05-27T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:21275">RHSA-2026:21275</Advisory>
        <Package name="rhui5/rhua-rhel9">rhui5/rhua-rhel9:1779798222</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:insights_proxy:1">
        <ProductName>Red Hat Lightspeed proxy 1</ProductName>
        <FixState>Affected</FixState>
        <PackageName>insights-proxy/insights-proxy-container-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_data_foundation:4">
        <ProductName>Red Hat Openshift Data Foundation 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>odf4/ocs-client-console-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_data_foundation:4">
        <ProductName>Red Hat Openshift Data Foundation 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>odf4/odf-console-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_data_foundation:4">
        <ProductName>Red Hat Openshift Data Foundation 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>odf4/odf-multicluster-console-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-42945
https://nvd.nist.gov/vuln/detail/CVE-2026-42945
https://depthfirst.com/nginx-rift
https://my.f5.com/manage/s/article/K000161019
    </References>
    <CSAw>True</CSAw>
</Vulnerability>