Sploitus

CVE-2026-42945

42 known exploits for CVE-2026-42945

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 Dos
≤ 4.7.0, 4.8.0
f5 Nginx Gateway Fabric
≤ 1.6.2, 2.5.1
f5 Nginx Ingress Controller
≤ 3.7.2, 4.0.1, 5.4.1
f5 Nginx Instance Manager
≤ 2.21.1
f5 Nginx Open Source
≤ 1.30.0
f5 Nginx Plus
≤ R36
Fix
Available
CVSS 4.0
9.2 CRITICAL
CVSS 3.1
8.1 HIGH
EPSS
66.0% (99th percentile)
Weakness
CWE-122, CWE-131
NVD status
Modified
Published
2026-05-13
CVE-2026-42945 at NVD
Authoritative description, scoring and affected products

42 known exploits for CVE-2026-42945

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Incorrect Calculation of Buffer Size in F5 Dos
2026-08-14 Kentox493GITHUB
NginxRift-Poc
2026-07-20 laohuang101GITHUB
Exploit for Incorrect Calculation of Buffer Size in F5 Dos
2026-07-01 arataneGITHUB
Exploit for Heap-based Buffer Overflow in F5 Dos
2026-06-22 azilRababeGITHUB
Exploit for CVE-2026-42945
2026-06-15 ushstGITHUB
Exploit for CVE-2026-42945
2026-06-14 sec-sysGITHUB
Exploit for CVE-2026-42945
2026-06-09 jenniferreire26GITHUB
Exploit for CVE-2026-42945
2026-06-04 simotaGITHUB
Exploit for CVE-2026-42945
2026-06-03 lowilolGITHUB
Exploit for CVE-2026-42945
2026-05-28 quantumworld-dpdns-ioGITHUB
Exploit for CVE-2026-42945
2026-05-26 niekaichengGITHUB
Exploit for CVE-2026-42945
2026-05-25 Ahmed-SoliGITHUB
Exploit for CVE-2026-42945
2026-05-25 karakapaku43GITHUB
Exploit for CVE-2026-42945
2026-05-25 nu0lGITHUB
Exploit for CVE-2026-42945
2026-05-25 bamov970GITHUB
Exploit for CVE-2026-42945
2026-05-23 webdev75950-uxGITHUB
Exploit for CVE-2026-42945
2026-05-22 F2u0a0d3GITHUB
Exploit for CVE-2026-42945
2026-05-20 gagaltotalGITHUB
Exploit for CVE-2026-42945
2026-05-20 yusufdalbudakGITHUB
Exploit for CVE-2026-42945
2026-05-19 imSre9GITHUB
Exploit for CVE-2026-42945
2026-05-19 RedCrazyGhostGITHUB
nginx-rift-private-lab
2026-05-19 0xDimasGITHUB
Exploit for CVE-2026-42945
2026-05-18 hnytglGITHUB
Exploit for CVE-2026-42945
2026-05-17 tal7aouyGITHUB
Exploit for CVE-2026-42945
2026-05-17 Renison-GohelGITHUB
Exploit for CVE-2026-42945
2026-05-16 dinosnGITHUB
nginx-rift-private-lab
2026-05-15 Hamid-KGITHUB
Exploit for CVE-2026-42945
2026-05-15 forxiucnGITHUB
Exploit for CVE-2026-42945
2026-05-15 chenqin231GITHUB
Exploit for CVE-2026-42945
2026-05-15 iammerrida-sourceGITHUB
Exploit for CVE-2026-42945
2026-05-15 jelasinGITHUB
Exploit for CVE-2026-42945
2026-05-15 byezeroGITHUB
Exploit for CVE-2026-42945
2026-05-14 fripariaGITHUB
Exploit for CVE-2026-42945
2026-05-14 p3Nt3st3r-sTArGITHUB
Exploit for CVE-2026-42945
2026-05-14 realityoneGITHUB
Exploit for CVE-2026-42945
2026-05-14 cipherspyGITHUB
Exploit for CVE-2026-42945
2026-05-14 enclave-aiGITHUB
Exploit for CVE-2026-42945
2026-05-14 nanwinataGITHUB
Exploit for CVE-2026-42945
2026-05-14 rheodevGITHUB
Exploit for CVE-2026-42945
2026-05-14 ChamsBouzaieneGITHUB
CVE-2026-42945
2026-05-13 f5UNKNOWN
Exploit for CVE-2026-42945
2026-05-12 depthfirstdisclosuresGITHUB