🚨 آسیبپذیری بحرانی NGINX Rift (CVE-2026-42945)
یک Heap Buffer Overflow با قدمت ۱۸ سال در ماژول Rewrite هسته NGINX کشف شد — امکان Remote Code Execution بدون احراز هویت.
🔴 CVSS Score: 8.1 (Critical)
🔴 نوع: Heap Buffer Overflow در ngx_http_rewrite_module
🔴 نسخههای آسیبپذیر:
• NGINX Open Source: 0.6.27 - 1.30.0
• NGINX Plus: R1 - R34
⚠️ Impact:
• Remote Code Execution (RCE)
• Denial of Service (DoS)
• Memory Disclosure (Private Keys, Credentials)
🎯 محیطهای پرخطر:
•Internet Reverse Proxies
• API Gateways
• Kubernetes Ingress Controllers
✅ Mitigation:
• آپدیت به NGINX 1.30.1+ یا 1.31.0+
• Audit فایلهای config برای patterns آسیبپذیر
• استفاده از named captures بهجای unnamed
گزارش کامل در Vulncity
🆔 @vulncity
Post #47
584
