Insecure Nginx Rewrite Rule Guidance in Google XML Sitemaps
The plugin’s admin dashboard suggested a block of Nginx rewrite rules that used unnamed PCRE captures with a question mark in the replacement string – the configuration pattern that triggers CVE-2026-42945, a heap overflow in Nginx’s ngx_http_rewrite_module. Administrators who copied those rules into their own nginx.conf reproduced the vulnerable pattern on their server. The suggested rules now use named captures instead; note that this updates only the guidance shown by the plugin and does not patch Nginx itself, so affected servers must still upgrade Nginx and re-copy the updated block from Settings – XML-Sitemap.
This vulnerability affects the following application versions:
- Google XML Sitemaps 4.1.2
- Google XML Sitemaps 4.1.3
- Google XML Sitemaps 4.1.4
- Google XML Sitemaps 4.1.5
- Google XML Sitemaps 4.1.6
- Google XML Sitemaps 4.1.7
- Google XML Sitemaps 4.1.8
- Google XML Sitemaps 4.1.9
- Google XML Sitemaps 4.1.10
- Google XML Sitemaps 4.1.11
- Google XML Sitemaps 4.1.12
- Google XML Sitemaps 4.1.13
- Google XML Sitemaps 4.1.14
- Google XML Sitemaps 4.1.15
- Google XML Sitemaps 4.1.16
- Google XML Sitemaps 4.1.17
- Google XML Sitemaps 4.1.18
- Google XML Sitemaps 4.1.19
- Google XML Sitemaps 4.1.20
- Google XML Sitemaps 4.1.21
- Google XML Sitemaps 4.1.22
- Google XML Sitemaps 4.1.23