<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:43:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:18029 — Critical: nginx security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:18029</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nginx, AlmaLinux:9: nginx-all-modules, AlmaLinux:9: nginx-core, AlmaLinux:9: nginx-filesystem, AlmaLinux:9: nginx-mod-devel, AlmaLinux:9: nginx-mod-http-image-filter, AlmaLinux:9: nginx-mod-http-perl, AlmaLinux:9: nginx-mod-http-xslt-filter, AlmaLinux:9: nginx-mod-mail, AlmaLinux:9: nginx-mod-stream&lt;/p&gt;
&lt;p&gt;nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nginx, AlmaLinux:9: nginx-all-modules, AlmaLinux:9: nginx-core, AlmaLinux:9: nginx-filesystem, AlmaLinux:9: nginx-mod-devel, AlmaLinux:9: nginx-mod-http-image-filter, AlmaLinux:9: nginx-mod-http-perl, AlmaLinux:9: nginx-mod-http-xslt-filter, AlmaLinux:9: nginx-mod-mail, AlmaLinux:9: nginx-mod-stream&lt;/p&gt;
&lt;p&gt;nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:18029</guid>
    </item>
    <item>
      <title>bdu:2026-06827</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06827</link>
      <description>bdu:2026-06827</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06827</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-42945</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42945</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nginx, Alpaquita:25: nginx, Alpaquita:stream: nginx&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nginx, Alpaquita:25: nginx, Alpaquita:stream: nginx&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42945</guid>
    </item>
    <item>
      <title>BIT-nginx-2026-42945 — NGINX ngx_http_rewrite_module vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bit-nginx-2026-42945</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nginx&lt;/p&gt;
&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: nginx&lt;/p&gt;
&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-nginx-2026-42945</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0591 — De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0591</link>
      <description>certfr-2026-avi-0591</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0591</guid>
    </item>
    <item>
      <title>EUVD-2026-366082</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366082</link>
      <description>EUVD-2026-366082</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366082</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42945</link>
      <description>&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42945</guid>
    </item>
    <item>
      <title>GHSA-gcgv-v5gf-c543</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gcgv-v5gf-c543</link>
      <description>&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gcgv-v5gf-c543</guid>
    </item>
    <item>
      <title>ICSA-26-188-03 — Hitachi Energy e-mesh EMS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-188-03</link>
      <description>&lt;p&gt;Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-188-03</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-42945 — NGINX ngx_http_rewrite_module vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42945</link>
      <description>msrc_CVE-2026-42945</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-42945</guid>
    </item>
    <item>
      <title>NCSC-2026-0164 — Kwetsbaarheid verholpen in NGINX ngx_http_rewrite_module</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0164</link>
      <description>NCSC-2026-0164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0164</guid>
    </item>
    <item>
      <title>OESA-2026-2405 — nginx security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2405</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: nginx&lt;/p&gt;
&lt;p&gt;NGINX is a free, open-source, high-performance HTTP server and reverse proxy,  as well as an IMAP/POP3 proxy server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2026-42945)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: nginx&lt;/p&gt;
&lt;p&gt;NGINX is a free, open-source, high-performance HTTP server and reverse proxy,  as well as an IMAP/POP3 proxy server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.(CVE-2026-42945)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2405</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10796-1 — nginx-1.31.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10796-1</link>
      <description>&lt;p&gt;nginx-1.31.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nginx-1.31.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10796-1</guid>
    </item>
    <item>
      <title>RHSA-2026:17417 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:17417</link>
      <description>&lt;p&gt;nginx: NGINX: Arbitrary Code Execution Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nginx: NGINX: Arbitrary Code Execution Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:17417</guid>
    </item>
    <item>
      <title>RLSA-2026:19159 — Critical: nginx security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19159</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nginx&lt;/p&gt;
&lt;p&gt;nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nginx&lt;/p&gt;
&lt;p&gt;nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nginx: NGINX: Arbitrary Code Execution Vulnerability (CVE-2026-42945)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19159</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21832-1 — Security update for nginx</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21832-1</link>
      <description>&lt;p&gt;Security update for nginx&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nginx&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21832-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42945</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42945</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:Pro:18.04:LTS: nginx, Ubuntu:Pro:20.04:LTS: nginx, Ubuntu:22.04:LTS: nginx, Ubuntu:24.04:LTS: nginx, Ubuntu:25.10: nginx, Ubuntu:26.04:LTS: nginx&lt;/p&gt;
&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:Pro:18.04:LTS: nginx, Ubuntu:Pro:20.04:LTS: nginx, Ubuntu:22.04:LTS: nginx, Ubuntu:24.04:LTS: nginx, Ubuntu:25.10: nginx, Ubuntu:26.04:LTS: nginx&lt;/p&gt;
&lt;p&gt;NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42945</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1527 — NGINX Open Source and NGINX Plus: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1527</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NGINX Open Source and NGINX Plus ausnutzen, um Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in NGINX Open Source and NGINX Plus ausnutzen, um Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1527</guid>
    </item>
  </channel>
</rss>
