CVE-2026-9256 sits in a narrow but dangerous corner of NGINX: rewrite rules that reuse overlapping PCRE captures can push a worker into denial of service and, under added conditions, into remote code execution.
A memory-safety flaw in NGINX’s rewrite path shows how ordinary request parsing can turn into denial of service, and in narrower conditions, remote code execution.
A critical flaw in NGINX’s rewrite engine turns a routine configuration pattern into a memory-corruption risk for internet-facing proxies, load balancers, and ingress tiers.
A long-lived flaw in NGINX rewrite handling can crash worker processes and, in narrower conditions, raise the ceiling to remote code execution.