<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:20:11.392335+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:18029</id>
    <title>ALSA-2026:18029 — Critical: nginx security update</title>
    <updated>2026-10-03T05:20:12.112686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: nginx, AlmaLinux:9: nginx-all-modules, AlmaLinux:9: nginx-core, AlmaLinux:9: nginx-filesystem, AlmaLinux:9: nginx-mod-devel, AlmaLinux:9: nginx-mod-http-image-filter, AlmaLinux:9: nginx-mod-http-perl, AlmaLinux:9: nginx-mod-http-xslt-filter, AlmaLinux:9: nginx-mod-mail, AlmaLinux:9: nginx-mod-stream</p>
<p>nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.</p>
<p>Security Fix(es):</p>
<p>* nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:18029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06827</id>
    <title>bdu:2026-06827</title>
    <updated>2026-10-03T05:20:12.112772+00:00</updated>
    <content>bdu:2026-06827</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06827"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42945</id>
    <title>BELL-CVE-2026-42945</title>
    <updated>2026-10-03T05:20:12.112790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: nginx, Alpaquita:25: nginx, Alpaquita:stream: nginx</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nginx-2026-42945</id>
    <title>BIT-nginx-2026-42945 — NGINX ngx_http_rewrite_module vulnerability</title>
    <updated>2026-10-03T05:20:12.112813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nginx</p>
<p>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nginx-2026-42945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0591</id>
    <title>certfr-2026-avi-0591 — De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T05:20:12.112838+00:00</updated>
    <content>certfr-2026-avi-0591</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0591"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366082</id>
    <title>EUVD-2026-366082</title>
    <updated>2026-10-03T05:20:12.112853+00:00</updated>
    <content>EUVD-2026-366082</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42945</id>
    <title>fkie_cve-2026-42945</title>
    <updated>2026-10-03T05:20:12.112864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gcgv-v5gf-c543</id>
    <title>GHSA-gcgv-v5gf-c543</title>
    <updated>2026-10-03T05:20:12.112889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gcgv-v5gf-c543"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-188-03</id>
    <title>ICSA-26-188-03 — Hitachi Energy e-mesh EMS</title>
    <updated>2026-10-03T05:20:12.112906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-188-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42945</id>
    <title>msrc_CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerability</title>
    <updated>2026-10-03T05:20:12.112925+00:00</updated>
    <content>msrc_CVE-2026-42945</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0164</id>
    <title>NCSC-2026-0164 — Kwetsbaarheid verholpen in NGINX ngx_http_rewrite_module</title>
    <updated>2026-10-03T05:20:12.112939+00:00</updated>
    <content>NCSC-2026-0164</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2405</id>
    <title>OESA-2026-2405 — nginx security update</title>
    <updated>2026-10-03T05:20:12.112954+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: nginx</p>
<p>NGINX is a free, open-source, high-performance HTTP server and reverse proxy,  as well as an IMAP/POP3 proxy server.

Security Fix(es):</p>
<p>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2026-42945)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10796-1</id>
    <title>openSUSE-SU-2026:10796-1 — nginx-1.31.0-1.1 on GA media</title>
    <updated>2026-10-03T05:20:12.112978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nginx-1.31.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10796-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:17417</id>
    <title>RHSA-2026:17417 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T05:20:12.112996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nginx: NGINX: Arbitrary Code Execution Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:17417"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19159</id>
    <title>RLSA-2026:19159 — Critical: nginx security update</title>
    <updated>2026-10-03T05:20:12.113011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: nginx</p>
<p>nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.</p>
<p>Security Fix(es):</p>
<p>* nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21832-1</id>
    <title>SUSE-SU-2026:21832-1 — Security update for nginx</title>
    <updated>2026-10-03T05:20:12.113032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nginx</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21832-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42945</id>
    <title>UBUNTU-CVE-2026-42945</title>
    <updated>2026-10-03T05:20:12.113051+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:Pro:18.04:LTS: nginx, Ubuntu:Pro:20.04:LTS: nginx, Ubuntu:22.04:LTS: nginx, Ubuntu:24.04:LTS: nginx, Ubuntu:25.10: nginx, Ubuntu:26.04:LTS: nginx</p>
<p>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1527</id>
    <title>WID-SEC-W-2026-1527 — NGINX Open Source and NGINX Plus: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:20:12.113085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NGINX Open Source and NGINX Plus ausnutzen, um Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1527"/>
  </entry>
</feed>
