AI Agent Uncovers 18-Year-Old Critical nginx Heap Bug Patched in May 2026
A critical heap vulnerability in nginx's URL rewriting module, tracked as CVE-2026-42945, was discovered by an AI-powered code audit tool after going undetected for roughly 18 years since version 0.6.27 in 2008. The flaw, scored 9.2 on CVSS v4.0 by NVD and F5, affects all nginx releases from 0.6.27 through 1.30.0, as well as NGINX Plus R32–R36. Patches were shipped on 13 May 2026 with nginx versions 1.30.1 and 1.31.0, and NGINX Plus R37. The bug stems from an uncleared internal flag in the regex substitution engine that causes a size mismatch between buffer allocation and data copying, enabling a heap overflow. Despite alarming estimates of 5.7 million potentially exposed servers, independent scans of real-world GitHub configurations found the vulnerable setup to be extremely rare in active production environments.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in