AI description
CVE-2026-9256, also known as "nginx-poolslip," is a heap buffer overflow vulnerability found within the `ngx_http_rewrite_module` component of NGINX Plus and NGINX Open Source. This flaw is triggered when a rewrite directive employs a regular expression pattern that contains distinct, yet overlapping, Perl-Compatible Regular Expression (PCRE) captures. The vulnerability manifests when a replacement string subsequently references multiple of these captures within a redirect or arguments context. Under these specific conditions, NGINX miscalculates the required length for the output after URI escaping, resulting in an out-of-bounds write within the worker process memory pool. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests. The primary outcome of this exploitation is typically a denial-of-service condition, caused by repeated crashes of the NGINX worker process. On systems where Address Space Layout Randomization (ASLR) is disabled or can be bypassed, this vulnerability could potentially enable remote code execution within the worker process context.
- Description
- NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Source
- f5sirt@f5.com
- NVD status
- Analyzed
- Products
- nginx_open_source, nginx_plus, dos, nginx_gateway_fabric, nginx_ingress_controller, nginx_instance_manager, waf, discovery, hardened_images, update_infrastructure, debian_linux, enterprise_linux
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
Introducing ENDGINX - 5 CVEs in NGINX with open models. We let loose GLM 5.1 and 5.2 by @Zai_org on the NGINX codebase. The work resulted in six fixed vulnerabilities across five CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, and CVE-2026-42533. First of
@mufeedvh
27 Jul 2026
5971 Impressions
25 Retweets
74 Likes
42 Bookmarks
1 Reply
1 Quote
🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-9256](https://t.co/BkZfTo1Ka7) NGINX Plus and NGINX Open Source h... https://t.co/BkZfTo1Ka7 #CVE #ZeroDay #PatchManagement
@MalwareObserver
23 Jul 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NGINX sürümleriniz güncel değilse güncelleyin; Rift (CVE-2026-42945) güvenlik açığı 1.30.0 ve öncesini etkiliyor. PoolSlip (CVE-2026-9256) güvenlik açığı 1.31.0 ve öncesini etkiliyor. Patchlenmiş sürümler: Nginx Open Source için 1.30.2 (stable) ya da
@ridvanyagli
8 Jun 2026
206 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-9256: CVE-2026-9256 — NGINX heap buffer overflow (CVSS 9.2 Critical) Overlapping PCRE captures in rewrite → heap overflow + heap info leak. Unauthenticated, remote. DoS + RCE path confirmed. Fixed: nginx 1.31.1 / 1.30.2 (9.2 → 1.31.1)
@lyrie_ai
8 Jun 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Nginx の脆弱性 nginx-poolslip CVE-2026-9256 が FIX:DoS とリモートコード実行の恐れ https://t.co/1FFS7FTVID NGINX の脆弱性 CVE-2026-9256 (nginx-poolslip) は、 設定ファイル内の rewrite ディレクティブにおいて、
@iototsecnews
29 May 2026
80 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 BREAKING: 1/3 of the internet is under active attack. Two critical zero-days (CVE-2026-42945 & CVE-2026-9256) just hit NGINX. The craziest part? The first bug hid in the codebase for 18 YEARS before an AI audit found it. Here is why this is a nightmare 🧵👇 https:/
@da7rkx0
27 May 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-9256: NGINX Heap Overflow Enables RCE on Web Servers https://t.co/71A1KA8wKa #Cybertrending #Cybernewsdaily #Cybersecurity
@CyberInsights1
25 May 2026
3 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-9256: NGINX Heap Overflow Enables RCE on Web Servers https://t.co/CzBODNWHSV #Cybertrending #Cybernewsdaily #Cybersecurity
@TheCyberDef
24 May 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-9256: NGINX Heap Overflow Enables RCE on Web Servers https://t.co/N17umRuu7B #Cybertrending #Cybernewsdaily #Cybersecurity
@unknownmatter19
24 May 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-9082 2 - CVE-2026-9256 3 - CVE-2026-44578 4 - CVE-2026-42897 5 - CVE-2024-23265 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
24 May 2026
133 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now! https://t.co/NgT2TKRTyB "Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolslip,…can be triggered by a remote, unauthenticated attacker over plain HTTP."
@catnap707
24 May 2026
98 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
curl -v "http://TARGET/$(python3 -c "print('+'*500, end='')")" nice test for CVE-2026-9256 aka nginx-poolslip
@MegaManSec
23 May 2026
89 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
NEW THREAT INTEL: CVE-2026-9256 Nginx-poolslip - Pre-auth heap overflow, bypasses CVE-2026-42945 patch. 9 detections, 15 IOCs. https://t.co/HThqQ69S36 #ThreatIntel #NGINX https://t.co/y7pFDfXADo
@threadlinqs
23 May 2026
78 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-9256見てる。結構条件厳しめかなぁ。
@k_kinzal
23 May 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"matchCriteriaId": "634D5CE2-039A-4D93-A03D-0FD7D0DEF686",
"versionEndIncluding": "0.9.7",
"versionStartIncluding": "0.1.17",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"matchCriteriaId": "07D3ADC7-5F8B-4709-B5D6-54C24904DC78",
"versionEndExcluding": "1.30.2",
"versionStartIncluding": "1.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_open_source:1.31.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A33B307E-A953-42D8-9ED6-975AA79C160F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "277F91F7-F75B-463E-A342-4624E52ED3ED",
"versionEndExcluding": "r36",
"versionStartIncluding": "r33",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:37.0.0.1:*:*:*:long-term_support:*:*:*",
"matchCriteriaId": "5D03EB59-E885-4614-B19C-BD441B4A56EC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:-:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "773FBF7A-CCEE-4B2A-A265-7938640D1B79",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "BEA2A3DC-1CD8-40CE-912F-6264314CFFA7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "6AF063B8-955E-44C5-9358-1A22C8187600",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "6B18D42C-A43E-4918-98EE-6A827B83EE3B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "9F8CE762-4BA6-413F-A8D8-BD7147C25FBD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p5:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "913BF7CA-FF4B-4BF5-83C4-ED2B92719A55",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r32:p6:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "EAEF93AB-9631-41AC-BFBC-A87F9162EC06",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:-:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "6FCF8770-25AF-4A07-916B-16F50357A44E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "D5C601A4-8DA6-443E-8284-6DCD34E4F3CB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "EB6684A4-3869-4C21-B87A-129C30C99C28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p3:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "B2AC5070-A6B7-440B-A45A-90E751FF103E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_plus:r36:p4:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "D7907F59-BBCC-4B5B-8BBC-92C14BB804D2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "0772572C-26F9-4FA4-B9E6-BA40ED59F569",
"versionEndIncluding": "4.7.0",
"versionStartIncluding": "4.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:dos:4.9.0:*:*:*:*:nginx:*:*",
"matchCriteriaId": "DACAC9CB-16D3-4F55-A466-70035779B387",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15B7F1FD-0C49-460F-9CB8-23DA730EC4BE",
"versionEndIncluding": "1.6.2",
"versionStartIncluding": "1.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:*",
"matchCriteriaId": "886468BC-0507-4C08-AAB6-EDF75A027C7A",
"versionEndExcluding": "2.6.2",
"versionStartIncluding": "2.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "E54B5C35-49D7-43F6-B57C-4606F75192CE",
"versionEndIncluding": "3.7.2",
"versionStartIncluding": "3.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "DB6D172C-2716-40B9-B74C-D3029EDD171F",
"versionEndIncluding": "4.0.1",
"versionStartIncluding": "4.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:continuous_releases:*:*:*",
"matchCriteriaId": "AC40FB98-DFE4-4097-AEAE-A113C7DB4F1B",
"versionEndExcluding": "5.4.3",
"versionStartIncluding": "5.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B20E450F-5E56-452F-9C7C-12D65AF5D0ED",
"versionEndExcluding": "2.22.1",
"versionStartIncluding": "2.17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "EB1118B4-3EA7-4A69-8259-86BB8837FC00",
"versionEndIncluding": "4.16.0",
"versionStartIncluding": "4.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "2DB79E6C-08B0-4341-BCBE-B8070DDAA7AF",
"versionEndIncluding": "5.8.0",
"versionStartIncluding": "5.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:f5:waf:*:*:*:*:*:nginx:*:*",
"matchCriteriaId": "DEDD5520-0B29-4D54-8AD5-8C0B2935A733",
"versionEndIncluding": "5.13.0",
"versionStartIncluding": "5.9.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B5B1D946-5978-4818-BF21-A43D9C1365E1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*",
"matchCriteriaId": "87DEB507-5B64-47D7-9A50-3B87FD1E571F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:update_infrastructure:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3FAF1DEF-A926-43D4-B94E-E7E02C813CD9",
"versionEndExcluding": "5.2",
"versionStartIncluding": "5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "7F6FB57C-2BC7-487C-96DD-132683AEB35D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]