← Findings

NGINX heap overflow in ngx_http_rewrite_module

Versions 0.6.27 through 1.30.0. CVSS 9.2. Active exploitation observed. If you run NGINX and your version is older than 1.30.1, this is the patch to ship first.

Versions 0.6.27 through 1.30.0. CVSS 9.2. Active exploitation observed. If you run NGINX in front of anything and your version is older than 1.30.1, this is the patch to ship first.

CVE-2026-42945 · NVD →