Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-42945] NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability

Summary

depthfirst's system found four remote memory-corruption bugs in NGINX, including a 2008-era heap overflow (CVE-2026-42945); a PoC shows RCE with ASLR off. rewrite/set users are at risk.
Published
Collected

original ↗

Related coverage

back