TGViewer
#! VulnCity #! VulnCity @vulncity · 247 subscribers
Post #47 584
🚨 آسیب‌پذیری بحرانی NGINX Rift (CVE-2026-42945)

یک Heap Buffer Overflow با قدمت ۱۸ سال در ماژول Rewrite هسته NGINX کشف شد — امکان Remote Code Execution بدون احراز هویت.

🔴 CVSS Score: 8.1 (Critical)

🔴 نوع: Heap Buffer Overflow در ngx_http_rewrite_module

🔴 نسخه‌های آسیب‌پذیر:
• NGINX Open Source: 0.6.27 - 1.30.0
• NGINX Plus: R1 - R34

⚠️ Impact:
• Remote Code Execution (RCE)
• Denial of Service (DoS)
• Memory Disclosure (Private Keys, Credentials)

🎯 محیط‌های پرخطر:
•Internet Reverse Proxies
• API Gateways
• Kubernetes Ingress Controllers

✅ Mitigation:
• آپدیت به NGINX 1.30.1+ یا 1.31.0+
• Audit فایل‌های config برای patterns آسیب‌پذیر
• استفاده از named captures به‌جای unnamed


گزارش کامل در Vulncity

🆔 @vulncity
More from @vulncity
  1. Oct 1, 2026🚀 کمپین «شروع امن» VulnCity شروع شد! خیلی از استارتاپ‌ها و شرکت‌های کوچیک، نیاز به امنیت…
  2. Sep 27, 2026یک وبینار خوب در مورد ADCS از SpecterOps 🤖زیرنویس توسط Qwen 3.7 plus ایجاد شده است. کانال…
  3. Sep 27, 2026photo post
  4. Sep 13, 2026۴۰ نکته برای کاهش Attack Surface و افزایش امنیت سرورهای Linux دانلود فایل 🆔 @vulncity
  5. Sep 12, 2026📌 آسیب‌پذیری بحرانی GitLab با CVSS 10 یک آسیب‌پذیری Path Traversal با شناسه CVE-2026-8570…
  6. Sep 7, 2026قابلیت‌های امنیتی Windows server 2025 📎 امنیت در زیرساخت‌های Windows Server همیشه یکی از…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →