CVE-2026-9256 — NGINX ngx_http_rewrite_module Overlapping PCRE Captures Heap Buffer Overflow RCE
Summary
CVE-2026-9256: nginx rewrite-module heap overflow when overlapping PCRE captures re-expand—giving heap-write and info-leak primitives for a viable RCE path; fixed in 1.31.1 and 1.30.2.
- CVE
- CVE-2026-9256
- Published
- Collected
Skip to content