CVE-2026-9256
CVE-2026-9256: 3 tracked advisory records across F5, NetApp, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
F5
1 advisory- Advisory severityCritical9.2
Critical [CVE-2026-9256] NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module
CVE-2026-9256Source published Source updated
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have…
- Affected products in this advisory
- NGINX Plus
- NGINX Open Source
- Source-reported affected versions
- NGINX Plus 37.0 before 37.0.1.1
- NGINX Plus R36 before R36 P5
- NGINX Plus R32 before R32 P7
- NGINX Open Source 1.31.0 before 1.31.1
2 more entries in the full advisory.
- Source-reported fixed versions
- 37.0.1.1
- R36 P5
- R32 P7
- 1.31.1
1 more entries in the full advisory.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
NetApp
1 advisory- Advisory severityHigh8.1
High [CVE-2026-9256] NGINX Vulnerability in NetApp Products
NTAP-20260605-0012Source published Source updated
Multiple NetApp products incorporate NGINX. NGINX versions prior to 1.30.2 and 1.31.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 1.30.2
- 1.31.0
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Red Hat
1 advisory- Advisory severityHigh8.1
High [CVE-2026-9256] code execution and denial of service
CVE-2026-9256Source published
code execution and denial of service. Red Hat rates this important (CVSS 8.1). Weakness: CWE-122. Affected package(s): nginx, nginx:1.26, nginx-main, nginx:1.24, discovery/discovery-ui-rhel9:1782756541. Resolved in Red Hat advisory RHSA-2026:29874 — update the affected packages (`sudo dnf update`).
- Affected products in this advisory
- NGINX Plus
- NGINX Open Source
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
5 more entries in the full advisory.
- Source-reported affected versions
- nginx-2:1.20.1-28.el9_8.3
- nginx:1.26-9080020260609152155.9
- nginx-main-1.30.2-1.hum1
- nginx:1.24-9080020260610161820.9
3 more entries in the full advisory.
- Source-reported fixed versions
- RHSA-2026:29874
- Mitigation guidance
- Update the affected package(s) to the fixed version shipped in RHSA-2026:29874 (`sudo dnf update` / `yum update`).
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.