Güvenlik Danışarlıklarına Dön

Nginx 1.30.1 (CVE-2026-42945)

CVE-2026-42945 is a heap buffer overflow in nginx's ngx_http_rewrite_module, fixed in nginx 1.30.1 and 1.31.0. An unauthenticated attacker can trigger it when a rewrite directive is followed by a rewrite, if, or set directive that uses an unnamed PCRE capture (like $1) in a replacement string containing a question mark, causing a worker restart — and code execution if ASLR is disabled. DirectAdmin server owners running nginx should update through CustomBuild.

High 8.1 CVSS
DirectAdmin

Etkilenen Sürümler

1.30.1

Varsayılan Güncelleme Komutu

cd /usr/local/directadmin/custombuild && ./build update_versions

SharedLicense lisansı altında bunun anlamı

Crafted HTTP requests can crash the nginx worker (denial of service), and on systems with ASLR disabled, arbitrary code execution is possible.

We recommend all DirectAdmin using Nginx to upgrade to the latest version 1.30.1 or 1.31.0. This release fixes the CVE-2026-42945 vulnerability.


	
	
		
		
			NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
		
		Click to expand...
	

More information about the vulnerability: https://depthfirst.com/nginx-rift

Sıkça Sorulan Sorular

What is CVE-2026-42945?
It is a vulnerability in the nginx ngx_http_rewrite_module (CWE-122, heap buffer overflow, CVSS 8.1). It triggers when a rewrite directive is followed by a rewrite, if, or set directive and an unnamed PCRE capture ($1, $2) appears in a replacement string that includes a question mark.
Which nginx versions fix CVE-2026-42945?
nginx 1.30.1 and 1.31.0 contain the fix. Any earlier 1.30.x or 1.31.x build running affected rewrite configurations should be upgraded; versions past End of Technical Support are not evaluated.
How do I update nginx on DirectAdmin?
Run: cd /usr/local/directadmin/custombuild && ./build update_versions — CustomBuild will bring nginx to the fixed release. Then confirm the running version with nginx -v.
How is CVE-2026-42945 exploited?
By sending crafted HTTP requests that hit a vulnerable rewrite configuration. The result is a heap buffer overflow that restarts the worker process; if ASLR happens to be disabled on the host, code execution becomes possible. Research details are published at depthfirst.com/nginx-rift.

Sisteminizi güvenlik açıkları açısından kontrol edin

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Sisteminizi Kontrol Edin