Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-9256 — NGINX ngx_http_rewrite_module Overlapping PCRE Captures Heap Buffer Overflow RCE

Summary

CVE-2026-9256: nginx rewrite-module heap overflow when overlapping PCRE captures re-expand—giving heap-write and info-leak primitives for a viable RCE path; fixed in 1.31.1 and 1.30.2.
CVE
CVE-2026-9256
Published
Collected

original ↗