CVE-2026-9256

Published May 22, 2026

Last updated 8 days ago

CVSS critical 9.2
Openresty
web application

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-9256, also known as "nginx-poolslip," is a heap buffer overflow vulnerability found within the `ngx_http_rewrite_module` component of NGINX Plus and NGINX Open Source. This flaw is triggered when a rewrite directive employs a regular expression pattern that contains distinct, yet overlapping, Perl-Compatible Regular Expression (PCRE) captures. The vulnerability manifests when a replacement string subsequently references multiple of these captures within a redirect or arguments context. Under these specific conditions, NGINX miscalculates the required length for the output after URI escaping, resulting in an out-of-bounds write within the worker process memory pool. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests. The primary outcome of this exploitation is typically a denial-of-service condition, caused by repeated crashes of the NGINX worker process. On systems where Address Space Layout Randomization (ASLR) is disabled or can be bypassed, this vulnerability could potentially enable remote code execution within the worker process context.

Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source
f5sirt@f5.com
NVD status
Analyzed
Products
nginx_open_source, nginx_plus, dos, nginx_gateway_fabric, nginx_ingress_controller, nginx_instance_manager, waf, discovery, hardened_images, update_infrastructure, debian_linux, enterprise_linux

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

f5sirt@f5.com
CWE-122
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-122

Social media

Hype score
Not currently trending
  1. Introducing ENDGINX - 5 CVEs in NGINX with open models. We let loose GLM 5.1 and 5.2 by @Zai_org on the NGINX codebase. The work resulted in six fixed vulnerabilities across five CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, and CVE-2026-42533. First of

    @mufeedvh

    27 Jul 2026

    5971 Impressions

    25 Retweets

    74 Likes

    42 Bookmarks

    1 Reply

    1 Quote

  2. 🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-9256](https://t.co/BkZfTo1Ka7) NGINX Plus and NGINX Open Source h... https://t.co/BkZfTo1Ka7 #CVE #ZeroDay #PatchManagement

    @MalwareObserver

    23 Jul 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 NGINX sürümleriniz güncel değilse güncelleyin; Rift (CVE-2026-42945) güvenlik açığı 1.30.0 ve öncesini etkiliyor. PoolSlip (CVE-2026-9256) güvenlik açığı 1.31.0 ve öncesini etkiliyor. Patchlenmiş sürümler: Nginx Open Source için 1.30.2 (stable) ya da

    @ridvanyagli

    8 Jun 2026

    206 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-9256: CVE-2026-9256 — NGINX heap buffer overflow (CVSS 9.2 Critical) Overlapping PCRE captures in rewrite → heap overflow + heap info leak. Unauthenticated, remote. DoS + RCE path confirmed. Fixed: nginx 1.31.1 / 1.30.2 (9.2 → 1.31.1)

    @lyrie_ai

    8 Jun 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Nginx の脆弱性 nginx-poolslip CVE-2026-9256 が FIX:DoS とリモートコード実行の恐れ https://t.co/1FFS7FTVID NGINX の脆弱性 CVE-2026-9256 (nginx-poolslip) は、 設定ファイル内の rewrite ディレクティブにおいて、

    @iototsecnews

    29 May 2026

    80 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. 🚨 BREAKING: 1/3 of the internet is under active attack. Two critical zero-days (CVE-2026-42945 & CVE-2026-9256) just hit NGINX. The craziest part? The first bug hid in the codebase for 18 YEARS before an AI audit found it. Here is why this is a nightmare 🧵👇 https:/

    @da7rkx0

    27 May 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. CVE-2026-9256: NGINX Heap Overflow Enables RCE on Web Servers https://t.co/71A1KA8wKa #Cybertrending #Cybernewsdaily #Cybersecurity

    @CyberInsights1

    25 May 2026

    3 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2026-9256: NGINX Heap Overflow Enables RCE on Web Servers https://t.co/CzBODNWHSV #Cybertrending #Cybernewsdaily #Cybersecurity

    @TheCyberDef

    24 May 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-9256: NGINX Heap Overflow Enables RCE on Web Servers https://t.co/N17umRuu7B #Cybertrending #Cybernewsdaily #Cybersecurity

    @unknownmatter19

    24 May 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Top 5 Trending CVEs: 1 - CVE-2026-9082 2 - CVE-2026-9256 3 - CVE-2026-44578 4 - CVE-2026-42897 5 - CVE-2024-23265 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    24 May 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now! https://t.co/NgT2TKRTyB "Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolslip,…can be triggered by a remote, unauthenticated attacker over plain HTTP."

    @catnap707

    24 May 2026

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. curl -v "http://TARGET/$(python3 -c "print('+'*500, end='')")" nice test for CVE-2026-9256 aka nginx-poolslip

    @MegaManSec

    23 May 2026

    89 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. NEW THREAT INTEL: CVE-2026-9256 Nginx-poolslip - Pre-auth heap overflow, bypasses CVE-2026-42945 patch. 9 detections, 15 IOCs. https://t.co/HThqQ69S36 #ThreatIntel #NGINX https://t.co/y7pFDfXADo

    @threadlinqs

    23 May 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2026-9256見てる。結構条件厳しめかなぁ。

    @k_kinzal

    23 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations