Posted inCloudflare WAF
WAF – WAF Release – 2026-05-15 – Emergency
This emergency release introduces two new rules to detect nginx heap buffer overflow and heap spray exploitation attempts targeting the rewrite module's is_args stale-state bug (CVE-2026-42945). Key Findings CVE-2026-42945: nginx Heap Buffer Overflow via Stale is_args in Rewrite Module Successful…





