PT-2026-42776 · F5+5 · Nginx Open Source+6
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NGINX Plus versions prior to 1.31.1
NGINX Open Source versions 0.1.17 through 1.31.0
Description
A flaw in the
ngx http rewrite module module occurs when a rewrite directive utilizes a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures and a replacement string that references multiple such captures in a redirect or arguments context. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests, leading to a heap buffer overflow in the NGINX worker process. This may result in a denial of service by forcing the process to restart or allow arbitrary code execution on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. ASLR is a security technique that randomly arranges the address space positions of key data areas of a process to make exploitation more difficult.Recommendations
Update NGINX Plus to version 1.31.1.
Update NGINX Open Source to version 1.31.1 or 1.30.2.
As a temporary mitigation, avoid using rewrite directives with overlapping PCRE captures in redirect or arguments contexts.
Exploit
Fix
DoS
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu