RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX’s ngx_http_rewrite_module introduced in 2008. The bug enables unauthenticated remote code execution against servers using rewrite and set directives.
NGINX Rift Exploit PoC Released for Critical CVE-2026-42945 RCE by Depthfirst. GitHub
Submitted 2 weeks ago by UnLocoPoco@lemmy.world to cybersecurity@infosec.pub
https://github.com/depthfirstdisclosures/nginx-rift