5 ms·
New Nginx Exploit
- FlyThruTheSun 5mo ago[dead]
- hetsaraiya 5mo agoJust saw this pop up — full public PoC for CVE-2026-42945 ("NGINX Rift"), a heap buffer overflow in NGINX's ngx_http_rewrite_module that's been there since 0.6.27 (2008). It triggers on a very common pattern: a `rewrite` directive (with an unnamed capture like $1/$2 and a `?` in the replacement string) followed by `set`, `if`, or another `rewrite`. The root cause is a classic two-pass script engine bug (length calculation vs. actual copy pass with ngx_escape_uri). The PoC turns it into unauthenticated RCE using cross-request heap feng shui + pool cleanup pointer corruption. Tested with a simple Docker setup. - Repo + Python exploit: https://github.com/DepthFirstDisclosures/Nginx-Rift https://github.com/DepthFirstDisclosures/Nginx-Rift - Full technical write-up: https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability https://depthfirst.com/research/nginx-rift-achieving-nginx-r... - F5 advisory + patches (1.31.0 / 1.30.1 for OSS, plus Plus updates): https://my.f5.com/manage/s/article/K000160932 https://my.f5.com/manage/s/article/K000160932 (or the latest K000161019) Affects basically any NGINX doing URL rewriting in front of apps/PHP/etc. Workaround mentioned is switching to named captures. The discovery angle is also interesting — it was found autonomously by depthfirst's security analysis tool after one-click onboarding of the NGINX source. Anyone running NGINX in production using rewrite rules? How are you checking your configs? Thoughts on the exploit chain or the AI-assisted finding process?
- deleted 5mo ago[deleted]
- stephenlf 5mo agoCrap
- hmokiguess 5mo agoI read that in my own voice, so relatable hahahaha
- Twirrim 5mo agoGiven it relies on ASLR being disabled, it's extremely unlikely you're at any risk from this.
- Tepix 5mo agoThat‘s wishful thinking
- bink 5mo agoThe exploit they chose assumes ASLR is disabled for simplicity's sake, but if you read the full writeup they say they could've used the vulnerability to map memory layout. It's nice to have ASLR but some types of vulnerabilities can be used to bypass it.
- jmaw 5mo agoWow, coming from the webdev world. It is so funny seeing NGINX, one of the widest used web servers in the world, on version 1.x. React is on version 19. Really shows how differently new vs. old software is designed and built, and not necessarily in a good way. https://world.hey.com/dhh/finished-software-8ee43637 https://world.hey.com/dhh/finished-software-8ee43637 https://josem.co/the-beauty-of-finished-software/ https://josem.co/the-beauty-of-finished-software/
- joecool1029 5mo agolighttpd still around too, on 1.4.82, not too much changed there.
- ranger_danger 5mo agoThey've been working on version 2.0 for many years now as well, I wonder when they think a release might happen.
- ranger_danger 5mo agoI chalk that up more to different versioning schemes rather than how much work is being done. If nginx changed whole numbers like react did, I bet it would be even higher.
- syoc 5mo agoI guess someone need to update https://0ver.org/ https://0ver.org/ then.
- shooly 5mo ago> not necessarily in a good way How do you think versioning works? You know that it's completely arbitrary and up to the author, right? Very ironic comment.
- deleted 5mo ago[deleted]
- 0x457 5mo ago
- danslo 5mo agoThis one's pretty bad but there are some preconditions. Requires a "rewrite" directive with a questionmark in the replacement string, and then a subsequent "set" directive that references a regex capture group (e.g. set $var $1). Also the POC assumes ASLR is disabled.
- dsr_ 5mo agoDoes any distro disable ASLR by default? If you were to do it by hand, nginx doesn't come to mind as a likely candidate.
- Bender 5mo agoNot the person you asked but I am not aware of any that disable ASLR by default, though most default to 1 which only enables ASLR for applications compiled to enable it vs 2 forcing it on or 3 on some distributions that use a hardened kernel. Rather than trusting any assumptions I prefer to run checksec [1] on every OS I touch. It's an old script but works just as well today as it did long ago. One may find that some applications are missing some basic hardening compile time options. The script is not an exhaustive test of all modern hardening options. Example of ASLR being forced on: # sysctl kernel.randomize_va_space kernel.randomize_va_space = 2 Typical invocation: checksec.sh --proc-all This invocation will list the status of RELRO, Stack Canary, NX/PaX, PIE of all running daemons. My CachyOS installation for example is missing Stack Canaries for all daemons. checksec.sh --fortify-proc 732 * Process name (PID) : sshd (732) * FORTIFY_SOURCE support available (libc) : Yes * Binary compiled with FORTIFY_SOURCE support: N Some additional compile time hardening options [2] and discussion [3]. Even Rust apparently has some compile time security related options. [1] - https://www.trapkit.de/tools/checksec/ https://www.trapkit.de/tools/checksec/ # some Linux repositories already contain "checksec". [2] - https://best.openssf.org/Compiler-Hardening-Guides/Compiler-Options-Hardening-Guide-for-C-and-C++.html https://best.openssf.org/Compiler-Hardening-Guides/Compiler-... [3] - https://news.ycombinator.com/item?id=43533516 https://news.ycombinator.com/item?id=43533516
- argee 5mo agoExample: https://github.com/DepthFirstDisclosures/Nginx-Rift/blob/main/env/nginx.conf#L39 https://github.com/DepthFirstDisclosures/Nginx-Rift/blob/mai...
- jcalvinowens 5mo agoThe POC disables aslr: https://github.com/DepthFirstDisclosures/Nginx-Rift/blob/main/env/entrypoint.sh#L4 https://github.com/DepthFirstDisclosures/Nginx-Rift/blob/mai...
- linkregister 5mo agoWorker processes are forked from the master, which means they receive the same memory layout. You get unlimited crashes against the worker. There's probably a way to exploit that to get a read oracle. At the very least this is a reliable denial of service. Depth First's full writeup: https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability https://depthfirst.com/research/nginx-rift-achieving-nginx-r...
- jcalvinowens 5mo agoSure, but I think the github README ought to make it more clear the POC as-is doesn't work against nginx on any current Linux distro.
- deleted 5mo ago[deleted]
- gavinsyancey 5mo agoSo you're not vulnerable to script-kiddies running the published PoC. Still probably vulnerable to to a sufficiently-motivated attacker.
- jcalvinowens 5mo agoI doubt it: aslr is not as easy to break on modern Linux as everyone in this thread wants to pretend it is. And anybody who actually cares so much about security that a compromised web frontend is the end of the world should be doing other things which would additionally mitigate this... I know they claimed they can bypass it: if that's true, they should publish it. The forking nature of nginx is uniquely bizarre and vulnerable, and I strongly suspect that's the only way they're pulling it off. I feel like that's the interesting thing here, not the buffer overrun.
- deleted 5mo ago[deleted]
- ChrisArchitect 5mo agoBetter links: https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability https://depthfirst.com/research/nginx-rift-achieving-nginx-r... (https://news.ycombinator.com/item?id=48126029 https://news.ycombinator.com/item?id=48126029) https://depthfirst.com/nginx-rift https://depthfirst.com/nginx-rift (https://news.ycombinator.com/item?id=48123365 https://news.ycombinator.com/item?id=48123365)
- panzi 5mo agoDoes Debian 12 have this patched? But I guess I'm not affected if I don't use `rewrite` or `set` anywhere?
- lpcvoid 5mo ago[dead]
- iririririr 5mo agoI find it very unlikely that anyone using nginx does NOT use `set` at least. Most nginx use cases are to end tls and then pass the request to node/php/go/etc. So, I bet you have at least one set with attacker controller data on a line like 'proxy_set_header X-Host $host;' edit: nvm. aparently named captures are not affect. Unless you have a $1 somewhere, it should be fine.
- babuskov 5mo agoThe default NGINX PHP integration uses this: # regex to split $uri to $fastcgi_script_name and $fastcgi_path fastcgi_split_path_info ^(.+?\.php)(/.*)$; set $path_info $fastcgi_path_info;
- wiredfool 5mo agoUbuntu has patched as of this morning. Debian doesn't look like they've patched trixie yet.
- rslashuser 5mo agoJust as a PSA, I found that "nginx -v" was not detailed about the version sufficient to check, but "apt list nginx" gave the full version number that was checkable, and indeed the 24.04 version of this morning (1.24.0-2ubuntu7.8) is patched.
- aftbit 5mo agohttps://security-tracker.debian.org/tracker/CVE-2026-42945 https://security-tracker.debian.org/tracker/CVE-2026-42945
- neomantra 5mo agoThe official F5 page is here: https://my.f5.com/manage/s/article/K000161019 https://my.f5.com/manage/s/article/K000161019 As noted elsewhere, ASLR protects you. While you are waiting for your affected platform to get the fix, they note the mitigation: "use named captures instead of unnamed captures in rewrite definition" "To mitigate this vulnerability for this example, replace $1 and $2 with the appropriate named captures, $user_id and $section" F5 patched 1.31.0 and 1.30.1. OpenResty has a patch for 1.27 and 1.29: https://github.com/openresty/openresty/commit/ee60fb9cf645c9573b98e7ba52f0401a11a1e416 https://github.com/openresty/openresty/commit/ee60fb9cf645c9... You can track OpenResty's (a Lua application server based on Nginx) progress here: https://github.com/openresty/openresty/issues/1119 https://github.com/openresty/openresty/issues/1119
- RagingCactus 5mo agoAs a security person it is tiring to see so many people here either directly claim or at least allude to the claim that this is somehow much less scary because the _published_ exploit does not bypass ASLR. The writeup claims there is a way to reliably bypass ASLR with this attack. And that is a good default assumption I would be willing to believe without evidence. ASLR is a defense-in-depth technique intended to make exploitation more difficult. In almost all cases it is only a matter of time and skill to also include an ASLR bypass. Both requirements continue being lowered by LLM agents every few weeks. It is only a matter of time (and probably not a lot of time) until a fully weaponized exploit is developed. It may be published, it may also be kept private. It is straight up wrong to say "if you have ASLR enabled, you're not at any risk from this" and saying this is extremely harmful for anyone that trusts claims like that. This wrong belief that you shouldn't care about security vulnerabilities because mitigations may make exploitation more difficult has already caused so much harm in the past. Be glad that modern mitigations exist, but patch your stuff asap. If you are a vendor, do not treat vulnerability reports as invalid because the researcher has not provided an ASLR bypass. Fix the root cause and hope mitigations buy you enough time to patch before you get owned.
- Fnoord 5mo agoSo the PoC works on MIPS out of the box. Tons of Linux/MIPS running around (Loongson64 seems to have KASLR on Linux).
- MisterTea 5mo agoDon't forget all the cheap WiFi routers with MT7688/MT7628/etc MIPS chips.
- Fnoord 5mo agoI was specifically thinking about the Edgerouter Lite running EdgeOS (Cavium SoC), but I also know some IP cameras do, and indeed some WAPs. For example, UniFi UAP-AC Lite and Pro variants. Each of these devices runs nginx for management (I suppose it could be disabled, each runs a variant of a SSH server as well). Worse, something like Shodan can find some of that on the internet.
- kitsune1 5mo ago[dead]
- ptx 5mo agoIs there a good alternative to Apache and Nginx that's written in a memory-safe language and not full of security holes? I briefly looked at Jetty (written in Java) and Caddy (written in Go) but they seem to have a history of vulnerabilities of other types (e.g. shell injection in Jetty) so I'm not sure they would be any better.
- embedding-shape 5mo agoCaddy been a breeze to use, bit sucky model with "we have thousands of binaries depending on what combination of plugins you want" instead of a proper plugin system, but if you're building it from source, it's pretty nifty and simple anyways.
- eikenberry 5mo agoRecompiling with the features you want is a great model for a free software project. So much simpler to write and maintain compared to a plugin system that it really makes more sense in a lot of cases.
- seanw444 5mo agoCan often also be noticeably more performant.
- vbernat 5mo agonginx had this defect for a long time too!
- dboreham 5mo agoGo doesn't support runtime linking, which is why "no plugins" (even though Go docs claim it does, no it doesn't).
- sharperguy 5mo agoI've switched to using traefik from caddy. For simple use cases it's a little more verbose in the configuration, but for more involved things like multiple load balancing backends, rewriting paths and headers and so on I've found it really good.
- pjmlp 5mo agoLooks into the CVE, ah an heap memory corruption, business as usual.
- jhatemyjob 5mo agotl;dr If you don't use ngx_http_rewrite_module, you're fine Honestly it's such a weird feature, if you're doing complicated redirects like this in nginx where PCRE is necessary, you should do it in your application code. And if you need speed use ngx_http_lua_module.
- PaulDavisThe1st 5mo agoWe do this for 3 sub-domains of ardour.org; there's no application code involved, because we're rewriting historical URLs to their current form, and the "application" doesn't do that or need to do that or need to know about that.
- jhatemyjob 5mo agoWhy not 302 instead?
- deleted 5mo ago[deleted]
- tredre3 5mo agoYour opinion is that if, for a godforsaken reason, someone needs to rewrite URLs in their web server, they should avoid PCRE (something designed for string manipulation) because it's overkill, and they should use Lua (a full programming language) instead? Am I understanding you correctly?
- jhatemyjob 5mo agoYes.
- GoblinSlayer 5mo agoBecause lua supports string manipulation without buffer overflows.
- geophph 5mo agoSomeone tell LowLevel
- trilogic 5mo agoGood to know, thanks. Wondering how long to the next.
- JSR_FDED 5mo ago> Exploitation uses cross-request heap feng shui First time I’ve seen feng shui used in this manner..?
- saagarjha 5mo agoIt's a common and slightly less problematic term for heap grooming.
- 100ms 5mo agoIs there a version of ingress-nginx somewhere with a fix for this?
- pando85 4mo ago[flagged]
- AmmyTang 5mo ago[dead]
- deleted 5mo ago[deleted]
- toyg 5mo agoWould this apply to non-Linux builds too, i.e. FreeBSD / OpenBSD...?
- kevcampb 5mo agoIt seems that Snyk isn't picking this up on our docker images. They have a vulnerability published for the nginx binary itself. https://security.snyk.io/vuln/SNYK-UNMANAGED-NGINX-16679754 https://security.snyk.io/vuln/SNYK-UNMANAGED-NGINX-16679754 But they've not released any vulnerability for the Alpine or Debian packages. Does anyone know what's happening here? Seems concerning that there's a 2 day old RCE not being picked up.
- kevcampb 5mo agoThey've just been released https://security.snyk.io/vuln/SNYK-DEBIAN13-NGINX-16732761 https://security.snyk.io/vuln/SNYK-DEBIAN13-NGINX-16732761 https://security.snyk.io/vuln/SNYK-ALPINE323-NGINX-16722461 https://security.snyk.io/vuln/SNYK-ALPINE323-NGINX-16722461 So it seems that Snyk is taking almost a week to get advisories out for an RCE