NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 9.2 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-filesystemUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-coreUpgrade nginx-mod-develUpgrade nginx-mod-http-image-filterUpgrade nginx-all-modulesUpgrade nginx-mod-streamUpgrade nginx-mod-http-perl | May 19, 2026 | May 18, 2026 |
| Alpine Linux | — | Upgrade nginx | May 15, 2026 | May 13, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-http-geoipUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-streamUpgrade nginx-coreUpgrade nginx-filesystemUpgrade nginx-mod-mailUpgrade nginx-mod-develUpgrade nginx-all-modulesUpgrade nginx | Jun 8, 2026 | Jun 8, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginx-debugsourceUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-coreUpgrade nginxUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-filesystemUpgrade nginx-mod-streamUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-develUpgrade nginx-mod-http-perl | May 28, 2026 | May 13, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | May 21, 2026 | May 19, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.30.1Upgrade to nginx version 1.31.0 | May 14, 2026 | May 13, 2026 |
| Oracle_linux | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-develUpgrade nginx-mod-http-perlUpgrade nginxUpgrade nginx-coreUpgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-filesystem | May 21, 2026 | May 13, 2026 |
| Redhat_linux | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-streamUpgrade nginx-mod-mail-debuginfoUpgrade nginx-debugsourceUpgrade nginx-coreUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-perlUpgrade nginxUpgrade nginx-core-debuginfoUpgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-filesystemUpgrade nginx-mod-devel | May 18, 2026 | May 13, 2026 |
| Rocky_linux | — | Upgrade nginx-mod-streamUpgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-develUpgrade nginx-coreUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-mailUpgrade nginx-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-debugsource | May 21, 2026 | May 19, 2026 |
| Ubuntu | — | Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade nginx-extrasUpgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade nginx-fullUpgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade nginx-coreUpgrade nginxUpgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade nginx (Ubuntu Pro) | May 25, 2026 | May 14, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 19, 2026 | May 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub