NGINX Rift (CVE-2026-42945): The 18-Year-Old Rewrite Module Bug That Lets One HTTP Request Own Your Web Server (2026 Patch Guide)
F5 disclosed a critical heap buffer overflow in NGINX's rewrite module on May 13, 2026, with a public PoC and active exploitation by May 16. Here is how the bug fires, how to audit your config in five minutes, and how to patch or mitigate before attackers find you.