FixVibe

high

Heap Buffer Overflow in NGINX ngx_http_rewrite_module (CVE-2026-42945)

CVE-2026-42945 affects NGINX Open Source and NGINX Plus release ranges when vulnerable rewrite-module configuration is loaded. FixVibe GitHub repo scans flag affected NGINX versions paired with matching rewrite configuration.

CVE-2026-42945CWE-122

Impact

CVE-2026-42945 is a heap-based buffer overflow in the NGINX rewrite module affecting NGINX Open Source and NGINX Plus release ranges listed by F5 and NVD [S1][S2]. In a deployed vulnerable runtime with the affected rewrite configuration loaded, traffic reaching the configured routes can crash worker processes and may allow code execution [S1][S2].

Root cause

The advisory ties the issue to rewrite-module configuration that combines positional PCRE capture handling with later rewrite-module directives [S1][S2]. Actual runtime risk depends on the NGINX release, vendor patch level, loaded include graph, deployed configuration, and whether affected routes are reachable.

Covered by FixVibe

FixVibe's GitHub repo scans flag repositories that combine an affected NGINX version with rewrite-module configuration matching this advisory, and show the files involved.

Fix

Upgrade to NGINX Open Source 1.30.1 or newer, or the fixed NGINX Plus patch release for your branch [S1][S2]. Rebuild and redeploy every image, host package, ingress image, or NGINX Plus runtime that can serve the affected configuration. Review rewrite-module configuration to prefer named captures or simpler routing, validate with nginx -t, reload NGINX, run normal route smoke tests, and rerun the FixVibe GitHub repo scan.