https://seclists.org/oss-sec/2026/q2/519: NGINX ngx_http_write_module vulnerability CVE-2026-42945
Published May 13, 2026
·Updated
Affected Software
2 affected components
Nginx NGINX Open Source>=0.6.27<=1.30.0
F5 NGINX Plus
Frequently Asked Questions
1
What is the severity of CVE-2026-42945?
CVE-2026-42945 is considered a medium severity vulnerability impacting NGINX Open Source and NGINX Plus.
2
How do I fix CVE-2026-42945?
To fix CVE-2026-42945, upgrade to the latest version of NGINX that includes the patch for this vulnerability.
3
Which NGINX versions are affected by CVE-2026-42945?
CVE-2026-42945 impacts specific versions of both NGINX Open Source and NGINX Plus that utilize the ngx_http_rewrite_module.
4
What type of vulnerability is CVE-2026-42945?
CVE-2026-42945 is a code execution vulnerability related to improper handling of rewrite directives in NGINX.
5
Is CVE-2026-42945 exploitable remotely?
Yes, CVE-2026-42945 can be exploited remotely, making it crucial for users to apply security updates promptly.