NGINX ngx_http_rewrite_module vulnerability
Published May 22, 2026
9.2
CRITICALCVSS 4.0
EPSS 2.70%
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
-
- Version 0.1.17StatusaffectedConstraints<=0.9.7
- Version 1.30.0StatusaffectedConstraints<1.30.2
- Version 1.31.0StatusaffectedConstraints<1.31.1
- Version
-
- Version 37.0StatusaffectedConstraints<37.0.1.1
- Version R32StatusaffectedConstraints<R32 P7
- Version R36StatusaffectedConstraints<R36 P5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| F5 | NGINX Open Source | unaffected |
| ||||||||||||
| F5 | NGINX Plus | n/a |
|
Configuration 1
- ≥ 0.1.17 · ≤ 0.9.7
- ≥ 1.0.0 · < 1.30.2
- 1.31.0
- ≥ r33 · < r36
- 37.0.0.1
- r32
- r32
- r32
- r32
- r32
- r32
- r32
- r36
- r36
- r36
- r36
- r36
Configuration 2
- ≥ 4.3.0 · ≤ 4.7.0
- 4.9.0
- ≥ 1.3.0 · ≤ 1.6.2
- ≥ 2.0.0 · < 2.6.2
- ≥ 3.5.0 · ≤ 3.7.2
- ≥ 4.0.0 · ≤ 4.0.1
- ≥ 5.0.0 · < 5.4.3
- ≥ 2.17.0 · < 2.22.1
- ≥ 4.10.0 · ≤ 4.16.0
- ≥ 5.2.0 · ≤ 5.8.0
- ≥ 5.9.0 · ≤ 5.13.0
Configuration 3
- n/a
- n/a
- ≥ 5.0 · < 5.2
- 11.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1782756541
Fixed · RHSA-2026:33313
Red Hat Enterprise Linux 10
nginx-2:1.26.3-6.el10_2.4
Fixed · RHSA-2026:29874
Red Hat Enterprise Linux 8
nginx:1.24-8100020260611094050.489197e6
Fixed · RHSA-2026:28921
Red Hat Enterprise Linux 9
nginx-2:1.20.1-28.el9_8.3
Fixed · RHSA-2026:28973
Red Hat Enterprise Linux 9
nginx:1.24-9080020260610161820.9
Fixed · RHSA-2026:28212
Red Hat Enterprise Linux 9
nginx:1.26-9080020260609152155.9
Fixed · RHSA-2026:29151
Red Hat Hardened Images
nginx-main-1.30.2-1.hum1
Fixed · RHSA-2026:20351
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-rhel9:1784794818
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1784794778
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1784795076
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Lightspeed proxy 1
insights-proxy/insights-proxy-container-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1782756541 | Fixed | RHSA-2026:33313 |
| Red Hat Enterprise Linux 10 | nginx-2:1.26.3-6.el10_2.4 | Fixed | RHSA-2026:29874 |
| Red Hat Enterprise Linux 8 | nginx:1.24-8100020260611094050.489197e6 | Fixed | RHSA-2026:28921 |
| Red Hat Enterprise Linux 9 | nginx-2:1.20.1-28.el9_8.3 | Fixed | RHSA-2026:28973 |
| Red Hat Enterprise Linux 9 | nginx:1.24-9080020260610161820.9 | Fixed | RHSA-2026:28212 |
| Red Hat Enterprise Linux 9 | nginx:1.26-9080020260609152155.9 | Fixed | RHSA-2026:29151 |
| Red Hat Hardened Images | nginx-main-1.30.2-1.hum1 | Fixed | RHSA-2026:20351 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1784794818 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1784794778 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1784795076 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Lightspeed proxy 1 | insights-proxy/insights-proxy-container-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this vulnerability, a rewrite directive must be configured with a regex pattern that uses distinct, overlapping PCRE captures and a replacement string referencing multiple such captures, limiting its exposure as this is not the default configuration. This issue allows an attacker to potentially execute arbitrary code or cause a denial of service by forcing the worker process to restart. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to these reasons, this flaw has been rated with an important severity.
Red Hat mitigation
To mitigate this vulnerability, use named captures instead of unnamed captures in rewrite definitions. For example, the following rewrite directive uses unnamed PCRE capture groups, $1 and $2: ~~~ rewrite ^/users/([0-9]+)/profile/(.*)$ /profile.php?id=$1&tab=$2 last; ~~~ To mitigate this vulnerability for this example, replace $1 and $2 with the appropriate named captures, $user_id and $section: ~~~ rewrite ^/users/(?<user_id>[0-9]+)/profile/(?<section>.*)$ /profile.php?id=$user_id&tab=$section last; ~~~
References (17)
- http://www.openwall.com/lists/oss-security/2026/05/22/14 Mailing List
- https://access.redhat.com/errata/RHSA-2026:20351 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28212 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28921 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28973 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29151 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29874 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33313 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:44481 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:58981
- https://access.redhat.com/security/cve/CVE-2026-9256 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2480746 Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2026/06/msg00023.html Mailing ListThird Party Advisory
- https://my.f5.com/manage/s/article/K000161377 vendor-advisoryMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-9256
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.json Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-9256
Change history (0)
No recorded changes yet.