A critical heap buffer overflow vulnerability, known as NGINX Rift, has been discovered in NGINX's ngx_http_rewrite_module, which can be exploited for unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-42945, was introduced in 2008 and affects servers using rewrite and set directives. A proof-of-concept exploit has been released, which uses cross-request heap feng shui and pool cleanup pointer corruption to achieve code execution. The vulnerability can be mitigated by updating NGINX to a patched version.