A critical vulnerability in NGINX’s source code, hidden since 2008, has finally been exposed, and a working exploit is already in the wild.
Security researchers at depthfirst have publicly released a proof-of-concept (PoC) exploit demonstrating unauthenticated remote code execution (RCE) against NGINX, the world’s most popular web server, powering nearly one-third of all websites globally.
The vulnerability, tracked as CVE-2026-42945 and codenamed NGINX Rift, carries a critical CVSS v4.0 score of 9.2 and has gone undetected for 18 years.
CVE-2026-42945 is a heap buffer overflow in NGINX’s ngx_http_rewrite_module. The flaw was introduced in NGINX version 0.6.27 in 2008 and affects every release up to and including 1.30.0.
Remarkably, a human researcher did not discover the bug; it was autonomously identified by depthfirst’s AI-powered source code analysis system after just six hours of scanning.
The root cause lies in a two-pass script engine used by NGINX to handle rewrite and set directives. During the first pass, NGINX calculates the amount of memory to allocate.
During the second pass, it copies data into that buffer. The problem: when a rewrite directive contains a question mark, it permanently sets an internal is_args flag on the main engine, but this flag is not propagated to the sub-engine used during length calculation.
As a result, the copy phase writes significantly more data than the allocated buffer can hold, causing a heap overflow with attacker-controlled content.
The vulnerability requires no authentication and is reachable directly from the public internet. An attacker needs to send a crafted HTTP request containing URI characters such as +, &, or % to trigger the overflow.
Because NGINX uses a multi-process architecture where crashed workers are automatically restarted with an identical heap layout, attackers can retry the exploit indefinitely without permanently taking down the server.
Researchers demonstrated a working PoC that achieved full RCE on systems with ASLR disabled and theorized that ASLR can be bypassed by progressively overwriting heap pointers byte by byte across multiple requests. The PoC source code has been published on depthfirst’s GitHub repository.
Three Additional CVEs Confirmed
Beyond CVE-2026-42945, NGINX confirmed three more vulnerabilities uncovered by the same analysis:
Affected Products and Fixes
The vulnerability impacts a wide range of F5 and NGINX products:
F5 released an official security advisory on May 13, 2026. Administrators are urged to upgrade to NGINX 1.31.0 or 1.30.1 immediately.
If an immediate upgrade is not possible, auditing NGINX configurations to remove or isolate rewrite and set directive combinations is a critical interim mitigation.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…