-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 HPE Aruba Networking Product Security Advisory ============================================== Advisory ID: HPESBNW05064 CVE: CVE-2026-42945 Publication Date: 2026-JUN-09 Status: CONFIRMED Severity: High Revision: 1 Title ===== Status of NGINX ngx_http_rewrite_module vulnerability (CVE-2026-42945) on HPE Aruba Networking Products. Overview ======== A vulnerability in the ngx_http_rewrite_module of NGINX Plus and NGINX Open Source may allow a remote unauthenticated attacker to trigger a heap buffer overflow using crafted HTTP requests under specific configuration conditions which may result in a denial-of-service condition or potentially remote code execution. Affected Products ================= HPE Aruba Networking - Management Software (Airwave): 8.3.0.6 and below. - Private 5G Management Dashboard: All supported versions. NOTE: HPE Aruba Networking does not evaluate or provide patches for software branches that have reached their End of Maintenance (EoM) milestone. For deployments running software versions that are past EoM, HPE Aruba Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation. Under Investigation ================= HPE Aruba Networking is currently assessing the potential security impact on the following HPE Aruba Networking products: - Analytics and Location Engine (ALE): All supported versions. - Central On Premises: All supported versions. NOTE: Products currently under investigation are not known to be affected by the listed CVE(s). Unaffected Products =================== Any HPE Aruba Networking products or software versions not specifically listed in the Affected Products or Under Investigation sections are not affected by the NGINX ngx_http_rewrite_module vulnerability (CVE-2026-42945). Details ======= NGINX ngx_http_rewrite_module vulnerability (CVE-2026-42945) - ------------------------------------------------------------ NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the "rewrite" directive with a query string is followed (in the same location) by the "if" or "set" directive with an unnamed Perl-Compatible Regular Expression (PCRE) capture. An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Source: https://my.f5.com/manage/s/article/K000161019. Internal Reference: VULN-365 Severity: High CVSS v3.1 Base Score: 8.1 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Discovery: This vulnerability was discovered and reported by Zhenpeng (Leo) Lin of depthfirst to F5. Resolution ========== To remediate this vulnerability, HPE Aruba Networking recommends applying the software updates listed below (as applicable). HPE Aruba Networking Management Software (Airwave) - Airwave 8.3.0.7 and above (ETA: First half of July 2026) HPE Aruba Networking Private 5G Management Dashboard - Private 5G Management Dashboard: 1.25.2.2 and above (ETA: First half of July 2026) Workaround ========== To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. You may contact HPE Services - HPE Aruba Networking for assistance if needed. For more information, please visit HPE Networking Support Portal at https://networkingsupport.hpe.com/home Exploitation and Public Discussion ================================== This CVE has been widely discussed in public. Additional details about this vulnerability is available at https://my.f5.com/manage/s/article/K000161019. At this time, HPE Aruba Networking is not aware of any publicly available exploitation tools or techniques that specifically target HPE Aruba Networking products. Revision History ================ Revision 1 / 2026-JUN-09 / Initial release HPE Aruba Networking SIRT Security Procedures ============================================== Complete information on reporting security vulnerabilities in HPE Aruba Networking products and obtaining assistance with security incidents is available at: http://www.hpe.com/support/security-response-policy For reporting NEW HPE Aruba Networking security issues, email can be sent to aruba-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key (c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information. -----BEGIN PGP SIGNATURE----- iQHLBAEBCAA1FiEEQT1cq06WWXH+NEKru7x8adyj7A4FAmooEhEXHHNlY3VyaXR5 LWFsZXJ0QGhwZS5jb20ACgkQu7x8adyj7A7BJQwAxlsiu/3RnZxWraWh5wZbWuZM glOkRxBIDCDAXe5GXKggxnhSxfHLhD0CMT2RaLlBnWgO2K5T99zSrFMExRb63Zb+ reliKrSpgiQeaO/765fVncQnb+CouWbLhXNWvWmuzGgDF5sCUyhtBUjtvCVb1HAH Lyi4imOtS1FsCFr/EiHj5ZmDrAzP4tfIHOtEecyTgj1fSbwBTysKDjoftHeCXBUK S3VhyKfRuaKHNe7veb5+tPYr4poc/3/5G2+r956eWx+6VsLbYOzzb/5Ka0kvu2Uj k1a3lzSMhWD+O0fy64VcewdG2xmOVgrlJ/XsbAxYcWTjxuSoQh9TL1d7UyfGH1ox 0AeJwO8jK4SQAII6IYaKvzco/4vxhSpimZ5yrPu5fhnyr1R5RBi3UN/tOuBJ8CkX OviPEQiHHzGT3+ZfOvrAQhEi0Wvy9yasYGxauqeIFQfIbIzUn/jAkuEoIS9UEKC5 Lel5s6VaieGtGT9gO82mXCIbJCxCs/TsyWziLDLG =pDs3 -----END PGP SIGNATURE-----