Insecure Nginx Rewrite Rule Guidance in Google XML Sitemaps

The plugin’s admin dashboard suggested a block of Nginx rewrite rules that used unnamed PCRE captures with a question mark in the replacement string – the configuration pattern that triggers CVE-2026-42945, a heap overflow in Nginx’s ngx_http_rewrite_module. Administrators who copied those rules into their own nginx.conf reproduced the vulnerable pattern on their server. The suggested rules now use named captures instead; note that this updates only the guidance shown by the plugin and does not patch Nginx itself, so affected servers must still upgrade Nginx and re-copy the updated block from Settings – XML-Sitemap.

This vulnerability affects the following application versions:

  • Google XML Sitemaps 4.1.2
  • Google XML Sitemaps 4.1.3
  • Google XML Sitemaps 4.1.4
  • Google XML Sitemaps 4.1.5
  • Google XML Sitemaps 4.1.6
  • Google XML Sitemaps 4.1.7
  • Google XML Sitemaps 4.1.8
  • Google XML Sitemaps 4.1.9
  • Google XML Sitemaps 4.1.10
  • Google XML Sitemaps 4.1.11
  • Google XML Sitemaps 4.1.12
  • Google XML Sitemaps 4.1.13
  • Google XML Sitemaps 4.1.14
  • Google XML Sitemaps 4.1.15
  • Google XML Sitemaps 4.1.16
  • Google XML Sitemaps 4.1.17
  • Google XML Sitemaps 4.1.18
  • Google XML Sitemaps 4.1.19
  • Google XML Sitemaps 4.1.20
  • Google XML Sitemaps 4.1.21
  • Google XML Sitemaps 4.1.22
  • Google XML Sitemaps 4.1.23

Fixed security issue related to trailing slashes

To make sure trailing forward slashes and backslashes removed if they exist in case of sm_b_baseurl and/or sm_b_style.

This vulnerability affects the following application versions:

  • Google XML Sitemaps 4.0.5
  • Google XML Sitemaps 4.0.6
  • Google XML Sitemaps 4.0.7
  • Google XML Sitemaps 4.0.7.1
  • Google XML Sitemaps 4.0.8
  • Google XML Sitemaps 4.0.9
  • Google XML Sitemaps 4.1.0