A heap buffer overflow in NGINX’s rewrite module lets an unauthenticated attacker crash worker processes with a single crafted HTTP request, and on hosts with ASLR disabled can be leveraged for remote code execution.
Read more about Emerging Threat: (CVE-2026-42945) NGINX Rift Heap Overflow in Rewrite Module