Post

Daniel Púa
Daniel Púa@devploit·
🚨 New nginx CVE: CVE-2026-42945, aka "NGINX Rift." Heap buffer overflow in ngx_http_rewrite_module. ~18-year-old bug. Unauthenticated. One crafted HTTP request. CVSS 9.2 Critical. If you run nginx in front of PHP / WordPress / API gateways, read on 🧵
Daniel Púa tweet media
English
1
6
26
3.6K
Daniel Púa
Daniel Púa@devploit·
Root cause: a size mismatch between two passes over the rewrite replacement string. If a rewrite uses an unnamed capture ($1, $2…) + a ? in the replacement + is followed by another rewrite/if/set, nginx sizes the buffer with one escape method and writes with another.
English
1
0
0
231
Paylaş