Nginx 1.30.1 (CVE-2026-42945)
CVE-2026-42945 is a heap buffer overflow in nginx's ngx_http_rewrite_module, fixed in nginx 1.30.1 and 1.31.0. An unauthenticated attacker can trigger it when a rewrite directive is followed by a rewrite, if, or set directive that uses an unnamed PCRE capture (like $1) in a replacement string containing a question mark, causing a worker restart — and code execution if ASLR is disabled. DirectAdmin server owners running nginx should update through CustomBuild.
प्रभावित संस्करण
1.30.1
डिफ़ॉल्ट अपडेट कमांड
cd /usr/local/directadmin/custombuild && ./build update_versions
SharedLicense लाइसेंस के तहत इसका अर्थ
Crafted HTTP requests can crash the nginx worker (denial of service), and on systems with ASLR disabled, arbitrary code execution is possible.
We recommend all DirectAdmin using Nginx to upgrade to the latest version 1.30.1 or 1.31.0. This release fixes the CVE-2026-42945 vulnerability.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Click to expand...
More information about the vulnerability: https://depthfirst.com/nginx-rift
अक्सर पूछे जाने वाले प्रश्न
What is CVE-2026-42945?
Which nginx versions fix CVE-2026-42945?
How do I update nginx on DirectAdmin?
How is CVE-2026-42945 exploited?
अपने सिस्टम में भेद्यताओं की जाँच करें
अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।
अपना सिस्टम जाँचें