CVE-2026-9256 | F5 NGINX Plus/NGINX Open Source prior 37.0.1.1/R32 P7/R36 P5 ngx_http_rewrite_module heap-based overflow (K000161377 / EUVD-2026-31444)
A vulnerability marked as critical has been reported in F5 NGINX Plus and NGINX Open Source. Affected by this issue is some unknown functionality of the component ngx_http_rewrite_module. The manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-9256. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.