PT-2026-42776 · F5+5 · Nginx Open Source+6

·

CVE-2026-9256

·

Published

2026-05-22

·

Updated

2026-07-23

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NGINX Plus versions prior to 1.31.1 NGINX Open Source versions 0.1.17 through 1.31.0
Description A flaw in the ngx http rewrite module module occurs when a rewrite directive utilizes a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures and a replacement string that references multiple such captures in a redirect or arguments context. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests, leading to a heap buffer overflow in the NGINX worker process. This may result in a denial of service by forcing the process to restart or allow arbitrary code execution on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. ASLR is a security technique that randomly arranges the address space positions of key data areas of a process to make exploitation more difficult.
Recommendations Update NGINX Plus to version 1.31.1. Update NGINX Open Source to version 1.31.1 or 1.30.2. As a temporary mitigation, avoid using rewrite directives with overlapping PCRE captures in redirect or arguments contexts.

Exploit

Fix

DoS

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:28212
ALSA-2026:28921
ALSA-2026:28973
ALSA-2026:29151
ALSA-2026:29874
BDU:2026-07182
BIT-NGINX-2026-9256
BIT-NGINX-GATEWAY-2026-9256
CVE-2026-9256
ECHO-5A21-3794-30F7
OPENSUSE-SU-2026:10852-1
OPENSUSE-SU-2026:21107-1
RHSA-2026:28212
RHSA-2026:28921
RHSA-2026:28973
RHSA-2026:29151
RHSA-2026:29874
SUSE-SU-2026:22178-1
SUSE-SU-2026:2307-1
SUSE-SU-2026:2370-1
USN-8354-1
USN-8375-1

Affected Products

Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu