CVE-2026-42945 (“NGINX Rift”) Patched in NGINX-RC Update (v1.31.0)

Written by

in

This release patches CVE-2026-42945 (“NGINX Rift”) and includes updated extensions to address a heap memory corruption issue.

What’s New

  • Security: Patched CVE-2026-42945 (“NGINX Rift”), a critical vulnerability affecting NGINX.

Deployment Information

This update is rolling out to all compatible servers. 

Servers with automatic updates enabled will be patched during the regular rollout window.

Important Notes

  • ⚠️ If you have disabled automatic updates, we recommend updating manually as soon as possible.
  • If you experience any issues after the update, please open a support ticket, and our team can revert your server to the previous version (v1.27.1). We’re actively monitoring the rollout. If you notice anything unusual, please let us know so we can investigate. 
  • No action is required unless you’ve disabled automatic updates