SEKurity GmbH Logo
Home / Tags / Rewrite Module

#Rewrite Module

1 Article tagged

[*] Filtering articles by tag: Rewrite Module
[+] Matching entries: 1
root@sekurity:~# ls -la /tags/rewrite-module/* _

CVE Research
sekurity-team

InSEKurity of the Week (CW20/2026): NGINX Rift -- 18-Year-Old Rewrite Module Heap Overflow, Unauthenticated DoS & Potential RCE (CVE-2026-42945)

A size-mismatch bug in the NGINX rewrite module lets a remote, unauthenticated attacker overflow the heap with a single crafted HTTP request -- reliable worker crashes for everyone, potential RCE where ASLR is off. CVSS 4.0 9.2, public PoC, exploited in the wild since 2026-05-16, ~5.7M exposed servers

01

root@sekurity:~# echo "End of results for tag: Rewrite Module"
End of results for tag: Rewrite Module
root@sekurity:~# _