NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 9.2 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginxUpgrade nginx-mod-mailUpgrade nginx-coreUpgrade nginx-filesystemUpgrade nginx-all-modulesUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-devel | Jun 25, 2026 | Jun 23, 2026 |
| Alpine Linux | — | Upgrade nginx | May 25, 2026 | May 22, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-debuginfoUpgrade nginx-mod-develUpgrade nginx-filesystemUpgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginx-coreUpgrade nginxUpgrade nginx-mod-http-geoip | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-all-modulesUpgrade nginx-core-debuginfoUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-filesystemUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-coreUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-debugsourceUpgrade nginx-mod-streamUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-devel | Jun 9, 2026 | May 22, 2026 |
| Debian | — | Upgrade nginx | Jun 8, 2026 | Jun 8, 2026 |
| Freebsd | — | Upgrade nginx | Jun 15, 2026 | May 22, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.30.2Upgrade to nginx version 1.31.1 | May 24, 2026 | May 22, 2026 |
| Redhat_linux | — | Upgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginxUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-core-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-mailUpgrade nginx-debuginfoUpgrade nginx-filesystemUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-coreUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-develUpgrade nginx-debugsourceUpgrade nginx-mod-stream | Jun 25, 2026 | May 22, 2026 |
| Rocky_linux | — | Upgrade nginx-mod-http-perlUpgrade nginx-mod-streamUpgrade nginxUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-develUpgrade nginx-debugsourceUpgrade nginx-mod-mailUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-core | Jun 25, 2026 | Jun 24, 2026 |
| Ubuntu | — | Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade nginx-coreUpgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade nginx-fullUpgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade nginxUpgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade nginx-extrasUpgrade nginx-extras (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade libnginx-mod-http-cache-purge (Ubuntu Pro) | Jun 2, 2026 | Jun 1, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 19, 2026 | May 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub