Remote code execution vulnerability found in NGINX, here are the affected versions

TL;DR AI
2 min readKey summary
DepthFirst found multiple memory corruption issues in NGINX source code, including CVE-2026-42945.
The confirmed flaw is a heap buffer overflow triggered under specific rewrite and set configuration conditions.
Affected versions include NGINX Open Source 0.6.27–1.30.0 and NGINX Plus R32–R36.
Fixed releases are NGINX 1.30.1, 1.31.0, and the corresponding Plus update releases.
Because exploitation may lead to unauthorized worker compromise and potentially code execution, admins should update and review configs immediately.



