Cyber Security News

PoC Released for 18-Year-Old NGINX Flaw Allowing Remote Code Execution

A critical vulnerability in NGINX’s source code, hidden since 2008, has finally been exposed, and a working exploit is already in the wild.

Security researchers at depthfirst have publicly released a proof-of-concept (PoC) exploit demonstrating unauthenticated remote code execution (RCE) against NGINX, the world’s most popular web server, powering nearly one-third of all websites globally.

The vulnerability, tracked as CVE-2026-42945 and codenamed NGINX Rift, carries a critical CVSS v4.0 score of 9.2 and has gone undetected for 18 years.

NGINX Flaw

CVE-2026-42945 is a heap buffer overflow in NGINX’s ngx_http_rewrite_module. The flaw was introduced in NGINX version 0.6.27 in 2008 and affects every release up to and including 1.30.0.

Remarkably, a human researcher did not discover the bug; it was autonomously identified by depthfirst’s AI-powered source code analysis system after just six hours of scanning.

The depthfirst system identified 4 remote memory corruption issues in NGINX (Source: Depthfirst)

The root cause lies in a two-pass script engine used by NGINX to handle rewrite and set directives. During the first pass, NGINX calculates the amount of memory to allocate.

During the second pass, it copies data into that buffer. The problem: when a rewrite directive contains a question mark, it permanently sets an internal is_args flag on the main engine, but this flag is not propagated to the sub-engine used during length calculation.

As a result, the copy phase writes significantly more data than the allocated buffer can hold, causing a heap overflow with attacker-controlled content.

The vulnerability requires no authentication and is reachable directly from the public internet. An attacker needs to send a crafted HTTP request containing URI characters such as +, &, or % to trigger the overflow.

Because NGINX uses a multi-process architecture where crashed workers are automatically restarted with an identical heap layout, attackers can retry the exploit indefinitely without permanently taking down the server.

Researchers demonstrated a working PoC that achieved full RCE on systems with ASLR disabled and theorized that ASLR can be bypassed by progressively overwriting heap pointers byte by byte across multiple requests. The PoC source code has been published on depthfirst’s GitHub repository.

Three Additional CVEs Confirmed

Beyond CVE-2026-42945, NGINX confirmed three more vulnerabilities uncovered by the same analysis:

  • CVE-2026-42946 (High, CVSS 8.3): Excessive memory allocation in ngx_http_scgi_module and ngx_http_uwsgi_module, producing a ~1 TB key length that crashes worker processes.
  • CVE-2026-40701 (Medium, CVSS 6.3): A use-after-free in ngx_http_ssl_module where a freed memory pointer is dereferenced after TLS connection closure during async OCSP DNS resolution.
  • CVE-2026-42934 (Medium, CVSS 6.3): An out-of-bounds read in ngx_http_charset_module caused by an off-by-one error when handling incomplete UTF-8 sequences across proxy buffer boundaries.

Affected Products and Fixes

The vulnerability impacts a wide range of F5 and NGINX products:

  • NGINX Open Source 0.6.27 through 1.30.0
  • NGINX Plus R32 through R36
  • NGINX Instance Manager 2.16.0 through 2.21.1
  • NGINX App Protect WAF 4.9.0–4.16.0 and 5.1.0–5.8.0
  • NGINX Ingress Controller 3.5.0–5.4.1

F5 released an official security advisory on May 13, 2026. Administrators are urged to upgrade to NGINX 1.31.0 or 1.30.1 immediately.

If an immediate upgrade is not possible, auditing NGINX configurations to remove or isolate rewrite and set directive combinations is a critical interim mitigation.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago