
Automatisiertes Toolkit zum Scannen, Ausnutzen und Patchen von CVE-2026-42945 (kritische RCE in nginx). Enthält Netzwerkscanner, Heap-Spray-Exploit und Batch-Patcher mit HTML/JSON-Berichterstattung.
Umfassendes Toolkit zum Scannen, Patchen und Testen von CVE-2026-42945 – eine kritische RCE-Schwachstelle in nginx
Dieses Toolkit bietet umfassende Werkzeuge zum Scannen, Patchen und Testen von CVE-2026-42945, einer kritischen Remote-Code-Ausführungs-Schwachstelle in nginx, die Versionen vor 1.26.3 (Mainline) und 1.24.1 (Stable) betrifft.
Die Schwachstelle nutzt eine fehlerhafte HTTP/2-Header-Analyse aus, wenn ASLR mittels Heap-Spray-Techniken deaktiviert ist.
| Eigenschaft | Wert |
|---|---|
| Schwachstellen-ID | CVE-2026-42945 |
| Typ | Remote Code Execution (RCE) |
| CVSS-Wert | 9.8 (Kritisch) |
| Betroffene Versionen | < 1.26.3 (Mainline) / < 1.24.1 (Stable) |
| Behobene Version | 1.26.3+ |
| Angriffsvektor | Fehlerhafte HTTP/2-Header-Analyse |
| Voraussetzung | ASLR auf dem Zielsystem deaktiviert |
Scannt ein Subnetz oder einen einzelnen Host, um verwundbare nginx-Installationen zu identifizieren.
Funktionen:
Patched automatisch verwundbare nginx-Instanzen auf die neueste sichere Version.
Funktionen:
Testet die Schwachstelle CVE-2026-42945 mittels Heap-Spray-Technik.
Funktionen:
paramiko (>= 3.0.0) - SSH client library
rich (>= 13.0.0) - Terminal formatting and progress bars
git clone https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit
cd CVE-2026-42945-NGINX-Rift-Toolkit
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

nginx_scanner.py)python3 nginx_scanner.py --subnet 192.168.1.0/24 --user root --key ~/.ssh/id_rsa
python3 nginx_scanner.py --subnet 192.168.1.10 --user root --key ~/.ssh/id_rsa
python3 nginx_scanner.py --subnet 10.0.0.0/30 --user admin --password "password"
python3 nginx_scanner.py --subnet 192.168.1.0/24 --port 2222 --user root --key ~/.ssh/id_rsa
python3 nginx_scanner.py --subnet 192.168.1.0/24 --user root --key ~/.ssh/id_rsa --output report.html
--subnet SUBNET Target subnet in CIDR format (required)
--user USER SSH username (default: root)
--password PASSWORD SSH password
--key KEY_PATH Path to SSH private key
--port PORT SSH port (default: 22)
--timeout TIMEOUT Connection timeout in seconds (default: 5)
--output FILE Output report file (HTML/JSON)
--workers WORKERS Number of concurrent threads (default: 20)
nginx_patcher.py)
python3 nginx_patcher.py --subnet 192.168.1.0/24 --user root --key ~/.ssh/id_rsa
python3 nginx_patcher.py --subnet 192.168.1.0/24 --user root --key ~/.ssh/id_rsa --dry-run
python3 nginx_patcher.py --subnet 192.168.1.0/24 --target-version 1.26.3 --user root --key ~/.ssh/id_rsa
python3 nginx_patcher.py --subnet 10.0.0.0/30 --port 2222 --user admin --password "password"
--subnet SUBNET Target subnet in CIDR format (required)
--user USER SSH username (default: root)
--password PASSWORD SSH password
--key KEY_PATH Path to SSH private key
--port PORT SSH port (default: 22)
--timeout TIMEOUT Connection timeout in seconds (default: 30)
--target-version VERSION Nginx version to patch to (default: latest)
--dry-run Show what would be patched without executing
--workers WORKERS Number of concurrent threads (default: 10)
exploit.py)
python3 exploit.py --target 192.168.1.100 --port 80
python3 exploit.py --target 192.168.1.100 --port 80 --command "cat /etc/passwd"
python3 exploit.py --target 192.168.1.100 --port 80 --spray 50
python3 exploit.py --target 192.168.1.100 --port 80 --verbose