CVE-2026-9256: Debian Linux

High severity, CVSS 8.1. EPSS: 2.7% chance of exploitation in the next 30 days.

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • Debian Debian Linux: version 11.0 only
  • F5 Dos: from 4.3.0, up to and including 4.7.0; version 4.9.0 only
  • F5 Nginx Gateway Fabric: from 1.3.0, up to and including 1.6.2; from 2.0.0, before 2.6.2 (fixed in 2.6.2)
  • F5 Nginx Ingress Controller: from 3.5.0, up to and including 3.7.2; from 4.0.0, up to and including 4.0.1; from 5.0.0, before 5.4.3 (fixed in 5.4.3)
  • F5 Nginx Instance Manager: from 2.17.0, before 2.22.1 (fixed in 2.22.1)
  • F5 Nginx Open Source: from 0.1.17, up to and including 0.9.7; from 1.0.0, before 1.30.2 (fixed in 1.30.2); version 1.31.0 only
  • F5 Nginx Plus: from r33, before r36 (fixed in r36); version 37.0.0.1 only; version r32 only; version r36 only
  • F5 Waf: from 4.10.0, up to and including 4.16.0; from 5.2.0, up to and including 5.8.0; from 5.9.0, up to and including 5.13.0
  • Red Hat Discovery: affected versions not specified
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Red Hat Hardened Images: affected versions not specified
  • Red Hat Update Infrastructure: from 5.0, before 5.2 (fixed in 5.2)

Published 2026-05-22. Last modified 2026-08-25.