Kryptovaluta-ticker:
sysadmin fra Cyber Security News

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

Guru Baran
Monday at 03:14
11 Visninger
0 Kommentarer
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx 1.30.4 (stable) and 1.31.3 (mainline), along with corresponding patches for NGINX Plus R33–R36 (fixed in R36 P7) and 37.0.0.1–37.0.2.1 (fixed in 37.0.3.1). The vulnerability is a pre-authentication remote code execution flaw rooted in a missing save/restore of PCRE capture state in nginx’s internal script engine. nginx evaluates expressions in two passes a LEN pass to measure buffer size and a VALUE pass to write the actual data, and both...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!