[CVE-2026-42945] NGINX Rift:借一个 18 年历史的老漏洞实现 NGINX 远程代码执行
depthfirst.com | 研究 | CVE-2026-42945 | #rce | #vulnerability-research | #memory-corruption | #heap-overflow | #nginx | #cve-2026-42945
摘要
depthfirst 系统在 NGINX 中发现 4 个远程内存破坏漏洞,包括一个可追溯至 2008 年的堆溢出(CVE-2026-42945):团队开发出关闭 ASLR 条件下的 RCE 概念验证,使用 rewrite 与 set 指令的配置存在风险。
- 发布时间
- 收录时间
Skip to content