⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-9256: NGINX Rewrite Module Overlapping Captures Bug

July 19, 2026

A heap overflow in NGINX's rewrite module due to overlapping captures, disclosed in May 2026. Similar class of flaw as CVE-2026-42533, involving two-pass script engine.