CVE-2026-429459.2 CRITICALexploited_in_wild
nginx — Active Exploitation of Heap Buffer Overflow
What it is: A heap buffer overflow in nginx's ngx_http_rewrite_module that went unnoticed for ~18 years, affecting nginx 0.6.27 through 1.30.0. CVSS 9.2.
Impact: Unauthenticated attackers can send crafted HTTP requests to crash nginx worker processes (reliable DoS). RCE is possible when ASLR is disabled on the host.
Mitigation: Patch to the latest Debian nginx package that includes the fix.