vmware / vmware/photon

nginx-cve-2026-42945

Open
#1,653 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
C
Stars
3.2k
Forks
692
PR merge metrics
No merged PRs in 30d

Description

Describe the bug

Hi,

The Photon OS nginx server is likely within the affected version range for CVE-2026-42945 (nginx Rift).

Version check

  • Affected range: NGINX Open Source 0.6.27 → 1.30.0
  • vmwarecna/nginx ships: nginx 1.7.11
  • 1.7.11 falls squarely inside that range. The bug was introduced in 2008 (~0.6.27) and only fixed in 1.30.1 / 1.31.0. So the code-level flaw is present in this image.

The vulnerable code is in ngx_http_rewrite_module, which is compiled into nginx by default, so the module is definitely present in the 1.7.11 build.

Reproduction steps

Please review the following prepared PRs and let me know whether they provide any benefit.

Expected behavior

patches for CVE-2026-42945 done.

Additional context

#1654 From a risk perspective, crafting co-disclosed CVEs into custom backports is usually a safe option. A version bump is "easier" if the risks are well-known.

 Summary by risk

  ┌──────────────────────────────────┬────────────┬─────────┬───────────────────┬─────┐
  │              Change              │    4.0     │ 5.0 ≤91 │      5.0 ≥92      │ 6.0 │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ TLSv1/1.1 disabled               │ ●          │ ●       │ already in 1.28.x │ ●   │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ proxy_http_version 1.1 default   │ ●          │ ●       │ ●                 │ ●   │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ upstream keepalive on by default │ ●          │ ●       │ ●                 │ ●   │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ Chunked LF-only rejected         │ ●          │ ●       │ ●                 │ ●   │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ RFC 3986 host validation         │ ●          │ ●       │ ●                 │ ●   │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ njs 0.9.0 String API removal     │ ● (static) │ ●       │ —                 │ ●   │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ njs 0.8.5 binary/UTF-8 split     │ ●          │ ●       │ —                 │ ●   │
  ├──────────────────────────────────┼────────────┼─────────┼───────────────────┼─────┤
  │ TLSv1.3 cert compression off     │ ●          │ ●       │ ●                 │ ●   │
  └──────────────────────────────────┴────────────┴─────────┴───────────────────┴─────┘

The 4.0 spec uses --add-module=njs-... (static) rather than --add-dynamic-module. With njs compiled into the nginx binary, any njs config script using the removed String methods or the old binary encoding API will cause nginx to fail to load the configuration on startup - there is no way to unload a static module at runtime. This is a harder failure mode than on 5.0/6.0 where the njs .so can simply not be loaded.

The two changes most likely to cause silent regressions in production are the proxy keepalive default and the proxy_http_version 1.1 default - both in 1.29.7 - since they alter outbound connection behaviour without any warning in nginx error logs.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the four linked PRs for the master, 4.0, 5.0 SPECS/91, and 5.0 branches, then compare their proposed CVE handling with the affected nginx 1.7.11 build. Check the njs static-module and nginx configuration changes described in the issue. Done means reaching a maintainer-approved decision on the patch or version-bump approach and applying it consistently to the relevant branches.

Written by the indexing model from the issue text.

Assessment

Tech stack
nginx
Domain
infrastructure, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.