An 18 year old heap buffer overflow in NGINX's rewrite module allows unauthenticated remote code execution through crafted HTTP requests.