Switch language한국어
Back to the list

Remote code execution vulnerability found in NGINX, here are the affected versions

TL;DR AI

Key summary

2 min read
  1. DepthFirst found multiple memory corruption issues in NGINX source code, including CVE-2026-42945.

  2. The confirmed flaw is a heap buffer overflow triggered under specific rewrite and set configuration conditions.

  3. Affected versions include NGINX Open Source 0.6.27–1.30.0 and NGINX Plus R32–R36.

  4. Fixed releases are NGINX 1.30.1, 1.31.0, and the corresponding Plus update releases.

  5. Because exploitation may lead to unauthorized worker compromise and potentially code execution, admins should update and review configs immediately.

Read the original