Threat Intel
NGINX CVE-2026-42945 Actively Exploited: Worker Crashes & RCE in the Wild
Incident Summary NGINX CVE-2026-42945, a heap buffer overflow in ngx_http_rewrite_module, is actively exploited in production environments. The flaw (present since 2008) allows unauthenticated remote attackers to crash nginx worker processes or execute code with crafted HTTP requests. Affected: NGINX versions 0.6.27 through 1.