This emergency release introduces two new rules to detect nginx heap buffer overflow and heap spray exploitation attempts targeting the rewrite module’s is_args stale-state bug (CVE-2026-42945).
Key Findings
CVE-2026-42945: nginx Heap Buffer Overflow via Stale is_args in Rewrite Module
Successful exploitation allows remote attackers to trigger a heap buffer overflow in nginx’s rewrite module by sending crafted URIs containing escapable characters. A length/copy pass mismatch in ngx_http_script_copy_capture_code() causes the copy pass to write escaped data into an undersized buffer, leading to heap corruption. This enables denial of service (worker process crash) and, with heap feng shui techniques, potential remote code execution.
We strongly recommend upgrading to nginx 1.30.1 (or later) immediately to address the underlying vulnerability. If you cannot upgrade immediately, avoid rewrite directives with ? in the replacement string followed by set or if referencing capture groups.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | 2013e3e58efe4b79a26e214f7e52be73 | N/A | nginx – Remote Code Execution – Buffer Overread – CVE:CVE-2026-42945 | N/A | Block | This is a new detection. |
| Cloudflare Managed Ruleset | 68226e83a4d14ee9a9c878469df0ee6c | N/A | nginx – Remote Code Execution – Heap Spray – CVE:CVE-2026-42945 | N/A | Block | This is a new detection. |
Source: Cloudflare
Latest Posts
- (Updated) Microsoft Viva Engage: Flexible targeting of Storyline Announcements [MC1183013]
![(Updated) Microsoft Viva Engage: Flexible targeting of Storyline Announcements [MC1183013] 2 pexels pixabay 462162](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Viva: Agent flexible query in Analytics Workbench [MC1403410]
![Microsoft Viva: Agent flexible query in Analytics Workbench [MC1403410] 3 pexels ketut subiyanto 4350217](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Update to Microsoft Enterprise Content Delivery Network (eCDN) analytics data retention (360 days to 180 days) [MC1403404]
![Update to Microsoft Enterprise Content Delivery Network (eCDN) analytics data retention (360 days to 180 days) [MC1403404] 4 pexels eye4dtail 122308](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Purview compliance portal: View-only role management enhancements [MC1403403]
![Microsoft Purview compliance portal: View-only role management enhancements [MC1403403] 5 pexels pixabay 269063](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![(Updated) Microsoft Viva Engage: Flexible targeting of Storyline Announcements [MC1183013] 2 pexels pixabay 462162](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-462162-150x150.webp)
![Microsoft Viva: Agent flexible query in Analytics Workbench [MC1403410] 3 pexels ketut subiyanto 4350217](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-ketut-subiyanto-4350217-150x150.webp)
![Update to Microsoft Enterprise Content Delivery Network (eCDN) analytics data retention (360 days to 180 days) [MC1403404] 4 pexels eye4dtail 122308](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-eye4dtail-122308-150x150.webp)
![Microsoft Purview compliance portal: View-only role management enhancements [MC1403403] 5 pexels pixabay 269063](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-pixabay-269063-150x150.webp)
![Copilot in SharePoint will start rolling out to all tenants as an opt-out preview starting in mid-June 2026 [MC1311968] 7 Copilot in SharePoint will start rolling out to all tenants as an opt-out preview starting in mid-June 2026 [MC1311968]](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-justin-hamilton-16109-92248-96x96.webp)