← Back

CVE-2026-9256

nvd nist
Published: May 22, 2026Modified: Aug 25, 2026

JSON object

Loading...
9.2
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f5sirt@f5.com (Secondary)

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected (35)

7 products
Nginx Open Source
Nginx Plus
Dos
Nginx Gateway Fabric
Nginx Ingress Controller
Nginx Instance Manager
Waf
1 product
Debian Linux
4 products
Discovery
Enterprise Linux
Hardened Images
Update Infrastructure
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 0.1.17 to 0.9.7
From 1.0.0 to 1.30.2
Version 1.31.0
F5
From r33 to r36
Version 37.0.0.1
Version r32
Version r32 p1
Version r32 p2
Version r32 p3
Version r32 p4
Version r32 p5
Version r32 p6
Version r36
Version r36 p1
Version r36 p2
Version r36 p3
Version r36 p4
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 4.3.0 to 4.7.0
Version 4.9.0
F5
From 1.3.0 to 1.6.2
From 2.0.0 to 2.6.2
F5
From 3.5.0 to 3.7.2
From 4.0.0 to 4.0.1
From 5.0.0 to 5.4.3
From 2.17.0 to 2.22.1
F5
From 4.10.0 to 4.16.0
From 5.2.0 to 5.8.0
From 5.9.0 to 5.13.0
Configuration C
7 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
All versions
Redhat
Version 10.0
Version 8.0
Version 9.0
All versions
From 5.0 to 5.2

References (15)

Source: f5sirt@f5.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Issue TrackingThird Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Third Party Advisory

Timeline

No history available yet.