[CVE-2026-42945] NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability
depthfirst.com | research | CVE-2026-42945 | #rce | #vulnerability-research | #memory-corruption | #heap-overflow | #nginx | #cve-2026-42945
Summary
depthfirst's system found four remote memory-corruption bugs in NGINX, including a 2008-era heap overflow (CVE-2026-42945); a PoC shows RCE with ASLR off. rewrite/set users are at risk.
- Published
- Collected
Skip to content