• News/
  • bleepingcomputer-20260514154341

18-year-old NGINX vulnerability allows DoS, potential RCE

BleepingComputer
·
Bill Toulas
·
Published May 14, 2026
·
Updated

An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution. The vulnerability is tracked as CVE-2026-42945 and received a critical severity rating of 9.2, based on the latest version of the Common Vulnerability Scoring System (CVSS). Three more memory corruption security issues were discovered in the same six-hour code scanning session by researchers at AI-native security company DepthFirst AI. NGINX is a massively used web server and reverse proxy platform, powering a third of the top ranked websites. It can efficiently balance load by distributing incoming network traffic to multiple backend servers and reduce load times by caching content. Owned and maintained by American tech firm F5, the web server is used by cloud providers, SaaS companies, banks, media platforms, e-commerce sites, and in Kubernetes clusters. CVE-2026-42945 is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0, which has been in the project’s code for roughly 18 years. According to DepthFirst, the vulnerability can be triggered when NGINX configurations use both the ‘rewrite’ and ‘set’ directives, a pattern the researchers say is common in API gateways and reverse proxy setups. The flaw stems from inconsistent state handling in NGINX’s internal script engine, which processes rewrites in two passes: one to calculate the am...

Read full article

Affected Software

2 affected components
F5 NGINX Open Source>=0.6.27<=1.30.0
F5 ngx_http_rewrite_module>=0.6.27<=1.30.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability discovered in the NGINX web server that is 18 years old and can lead to denial of service and possible remote code execution.

2

What security implications are discussed?

The vulnerability allows for denial of service attacks and, under specific conditions, could potentially enable remote code execution.

3

What products or software are affected by this vulnerability?

The affected products include F5 NGINX Open Source and the F5 ngx_http_rewrite_module, particularly versions between 0.6.27 and 1.30.0.

4

How was the vulnerability discovered?

The flaw was identified using an autonomous scanning system designed to detect vulnerabilities in software.

5

What should users of affected software do in response to this vulnerability?

Users should consider updating their affected NGINX software and related modules to mitigate the risk associated with this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203