CRITICAL: 18-Year-Old NGINX Rift Vulnerability (CVE-2026-42945) Lets Unauthenticated Attackers Hijack the World's Top Web Server
A heap-based buffer overflow in NGINX's ubiquitous ngx_http_rewrite_module, dubbed NGINX Rift and tracked as CVE-2026-42945, has been quietly sitting in the codebase since 2008. The flaw rates 9.2 on CVSS v4, requires no authentication, and has a public proof-of-concept available. Every NGINX Open Source build from 0.6.27 through 1.30.0 and every NGINX Plus release from R32 through R36 is affected.