Iniciar sesión Registro
Anuncios
Tu espacio publicitario
Reserva este slot exclusivo para el periodo elegido.
Comprar publicidad →
Logotipo de la comunidad de telegram - CatOps
Añadido 06 dic. 2025

CatOps

@catops
Número de suscriptores: 5 059
Fotos: 94
Videos: 5
Enlaces: 2,660
Descripción:
DevOps and other issues by Yurii Rochniak (@grem1in) - SRE @ Preply && Maksym Vlasov (@MaxymVlasov) - Engineer @ Star. Opinions on our own. We do not post ads including event announcements. Please, do not bother us with such requests!
Fuente

CatOps | Continuing with security advisory.NGINX ngx_http_rewrite_module vulner...

Logotipo de la comunidad de telegram - CatOps CatOps @catops
1 420 Vistas/Alcance 2026-05-14 14:31 Mensaje №2905
Continuing with security advisory.NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945.~NGINX Plus and NGINX Open Source have a vulnerability in the *ngx_http_rewrite_module* module. This vulnerability exists when the *rewrite* directive is followed by a *rewrite*, *if*, or *set* directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. (CVE-2026-42945) Don't confuse the F5's NGINX Ingress Controller with the community-led ingress-nginx, that is deprecated now.In any case, though, if you're using the ngx_http_rewrite_module (and it's widely used!), you are likely vulnerable.#security