CVE-2026-9256
NGINX ngx_http_rewrite_module vulnerability
Weakness-Klassen (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-07-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:44481
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+5) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+8)
- CVE Translated2026-07-23 12:10 UTC· nvd@nist.gov
- Translation: Title: NGINX Plus y NGINX Open Source de F5, Description: NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_rewrite_module. Esta vulnerabilidad existe cuando una directiva de reescritura utiliza un patrón de expresión regular (regex) con capturas de expresiones regulares compatibles con Perl (PCRE) distintas y superpuestas (por ejemplo, ^/((.*))$) y una cadena de reemplazo que hace referencia a múltiples de dichas capturas (por ejemplo, $1$2) en un contexto de redirección o de argumentos. Un atacante no autenticado, junto con condiciones fuera de su control, puede explotar esta vulnerabilidad enviando solicitudes HTTP manipuladas. Esto puede causar un desbordamiento de búfer de pila en el proceso de trabajador de NGINX, lo que lleva a un reinicio. Además, los atacantes pueden ejecutar código en sistemas con la aleatorización del espacio de direcciones (ASLR) deshabilitada o cuando el atacante puede eludir ASLR. Nota: Las versiones de software que han alcanzado el fin del soporte técnico (EoTS) no se evalúan.
- Initial Analysis2026-06-16 19:59 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* versions from (including) r32 up to (including) r36 *cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* versions from (including) 0.1.17 up to (including) 0.9.7 *cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (including) 1.30.1 *cpe:2.3:a:f5:nginx_open_source:1.31.0:*:*:*:*:*:*:* *cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* versions from (including) 37.0.0 up to (excluding) 37.0.1.1
- Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/05/22/14 Types: Mailing List, Third Party Advisory
- Reference Type: F5 Networks: https://my.f5.com/manage/s/article/K000161377 Types: Mitigation, Vendor Advisory
Beschreibung
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Quelle: MSRC
Quellen & Referenzen
- http://www.openwall.com/lists/oss-security/2026/05/22/14web
- https://my.f5.com/manage/s/article/K000161377web
- https://nvd.nist.gov/vuln/detail/CVE-2026-9256web
- https://lists.debian.org/debian-lts-announce/2026/06/msg00023.htmlweb
- https://access.redhat.com/errata/RHSA-2026:20351web
- https://access.redhat.com/errata/RHSA-2026:28212web
- https://access.redhat.com/errata/RHSA-2026:28921web
- https://access.redhat.com/errata/RHSA-2026:28973web
- https://access.redhat.com/errata/RHSA-2026:29151web
- https://access.redhat.com/errata/RHSA-2026:29874web
- https://access.redhat.com/errata/RHSA-2026:33313web
- https://access.redhat.com/security/cve/CVE-2026-9256web
- https://bugzilla.redhat.com/show_bug.cgi?id=2480746web
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.jsonweb
- https://access.redhat.com/errata/RHSA-2026:44481web