NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 9.2 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginx-mod-mailUpgrade nginx-filesystemUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginxUpgrade nginx-mod-develUpgrade nginx-all-modulesUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginx-core | May 19, 2026 | May 18, 2026 |
| Alpine Linux | — | Upgrade nginx | May 15, 2026 | May 13, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-streamUpgrade nginx-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filterUpgrade nginx-coreUpgrade nginx-mod-http-geoipUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mailUpgrade nginx-mod-develUpgrade nginx-filesystemUpgrade nginxUpgrade nginx-all-modules | Jun 8, 2026 | Jun 8, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-filesystemUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-mod-develUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-core-debuginfoUpgrade nginxUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-coreUpgrade nginx-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-debugsourceUpgrade nginx-mod-http-xslt-filter | May 28, 2026 | May 13, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | May 21, 2026 | May 19, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.30.1Upgrade to nginx version 1.31.0 | May 14, 2026 | May 13, 2026 |
| Oracle_linux | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-streamUpgrade nginx-mod-develUpgrade nginx-all-modulesUpgrade nginx-coreUpgrade nginxUpgrade nginx-filesystemUpgrade nginx-mod-mail | May 21, 2026 | May 13, 2026 |
| Redhat_linux | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-coreUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-streamUpgrade nginx-debugsourceUpgrade nginx-mod-http-image-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-filesystemUpgrade nginx-mod-develUpgrade nginx-mod-mailUpgrade nginx-core-debuginfoUpgrade nginx-all-modules | May 18, 2026 | May 13, 2026 |
| Rocky_linux | — | Upgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-mailUpgrade nginx-debuginfoUpgrade nginx-debugsourceUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-develUpgrade nginxUpgrade nginx-mod-streamUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-core-debuginfoUpgrade nginx-coreUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-http-xslt-filter | May 21, 2026 | May 19, 2026 |
| Ubuntu | — | Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade nginx-fullUpgrade nginx-extras (Ubuntu Pro)Upgrade nginx-extrasUpgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade nginxUpgrade nginx-coreUpgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro) | May 25, 2026 | May 14, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 19, 2026 | May 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub