TKGI and CVE-2026-42945
search cancel

TKGI and CVE-2026-42945

book

Article ID: 441032

calendar_today

Updated On:

Products

VMware Tanzu Kubernetes Grid Integrated Edition

Issue/Introduction

Customers using TKGi or TKGIMC may be concerned about security vulnerability CVE-2026-42945. Security scanners may flag the NGINX rewrite module ngx_http_rewrite_module as potentially allowing remote attackers to execute arbitrary code.

Environment

TKGi and TKGIMC

Cause

CVE-2026-42945 is a vulnerability identified in the ngx_http_rewrite_module of certain NGINX versions. It involves how rewrite rules are processed, which could theoretically be exploited for remote code execution.

Resolution

Neither TKGi or TKGIMC are impacted by CVE-2026-42945.

TKGi is not bundled with Nginx.

TKGIMC is bundled with Nginx but ngx_http_rewrite_module module is not used.

Additional Information

For any TKGI workloads using Bitnami Nginx, please upgrade Nginx images or helm charts

https://community.broadcom.com/tanzu/blogs/beltran-rueda-borrego/2026/05/14/critical-nginx-rce-vulnerability-cve-2026-42945