Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
nginx-cve-fix — Source-built nginx 1.25.5 container with backported CVE-2026-42945 fix, OpenSSL bump, full provenance chain, and VEX attestation. | Kitploit
Tools/GitHubGitHub/barappteam/nginx-cve-fix
Vulnerability ScannersContainer SecurityVulnerability AnalysisConfiguration AuditingDevSecOpsSupply Chain Security
GitHubbarappteam/nginx-cve-fix

nginx-cve-fix

Source-built nginx 1.25.5 container with backported CVE-2026-42945 fix, OpenSSL bump, full provenance chain, and VEX attestation.

View Repository
224 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Nginx CVE Fix - Source-Built Drop-in for nginx:1.25-bookworm

A source-built nginx 1.25.5 container image that remediates two CVEs present in the official nginx:1.25-bookworm image while preserving upstream runtime behavior.

CVEComponentSeverityTechniqueVerification model
CVE-2024-6119OpenSSL / libssl3HighDependency version bumpScanner-verifiable: libssl3 3.0.20 visible in dpkg database
CVE-2026-42945nginx ngx_http_rewrite_moduleCriticalBackported source patchProvenance-verifiable: patch derivation + regression test + build attestation + VEX

These represent two distinct remediation models:

  1. Version bump (CVE-2024-6119) - the fixed library version is directly visible to scanners via the dpkg database. No additional attestation needed.
  2. Source backport (CVE-2026-42945) - the package version remains 1.25.5, so scanners cannot distinguish the patched binary from an unpatched one. Remediation is demonstrated through source provenance, build-time verification, and regression testing. VEX provides the scanner-layer signal.

Parity status

The nginx -V configure arguments of this image match those of nginx:1.25-bookworm (compared character-by-character after normalizing the -ffile-prefix-map build path; verified in test/compat.py::test_nginx_version). The test suite (make test) validates 89 assertions covering image metadata, dynamic modules, filesystem layout, entrypoint behavior, dpkg packaging, and HTTP request handling against the live upstream image.

Known differences from upstream (not validated as identical):

  • The built with OpenSSL X.X.X line in nginx -V reflects the builder's libssl-dev version, which may differ from upstream's compile-time OpenSSL.
  • Binary content is not byte-for-byte identical (different compilation environment, different toolchain invocation timestamps).
  • The image package set differs - debian:bookworm-slim base rather than the official image's inherited package tree.
  • Runtime libssl3 version is whatever bookworm currently provides (3.0.20 at time of writing), not the pinned version in the upstream image.

Quick Start

# Build everything (builder → .deb → final image)
make image

# Run automated compatibility tests
make test

# Run CVE-2026-42945 regression test
make test-cve

# Verify patch provenance (re-derives from upstream tarballs)
make verify-patch

# Scan and demonstrate VEX
make scan

One command to build, test, and scan:

make all

Repository Structure

build/
  Dockerfile.build          Builder image (debian:bookworm-slim + compilation deps)
  build.sh                  Fetch → verify → patch → compile → package nginx
  generate-vex.sh           Generate OpenVEX document for backported CVE
  verify-patch.sh           Re-derive patch from upstream tarballs (audit tool)
  patches/
    CVE-2026-42945.patch           Backported one-line fix from nginx 1.30.1
    CVE-2026-42945.provenance.json Machine-readable patch provenance and derivation metadata

test/
  compat.py                 89-assertion compatibility test suite (runs against live upstream)
  test_cve_2026_42945.py    CVE-specific regression test (exercises vulnerable code path)

artifacts/
  patch-attestation.json    Build-time patch attestation (tracked)
  nginx_*.deb               Compiled package (gitignored - rebuilt via `make build-source`)
  nginx                     Compiled binary (gitignored)
Containerfile               Final runtime image definition
Makefile                    Orchestrates build → test → scan pipeline
vex.json                    Generated OpenVEX v0.2.0 document
baseline-trivy.txt          Point-in-time Trivy scan of nginx:1.25-bookworm
baseline-grype.txt          Point-in-time Grype scan of nginx:1.25-bookworm
fixed-trivy.txt             Trivy scan of the fixed image
fixed-grype.txt             Grype scan of the fixed image (without VEX)
fixed-grype-vex.txt         Grype scan of the fixed image (with VEX applied)

Build Process

Architecture

debian:bookworm-slim (builder)
  └─ build.sh
       ├─ curl nginx-1.25.5.tar.gz (SHA256-verified)
       ├─ curl njs-0.8.4 from github.com/nginx/njs
       ├─ patch -p1 < CVE-2026-42945.patch
       ├─ ./configure (flags identical to upstream nginx -V)
       ├─ make: release binary, debug binary, 4 dynamic module families (×2 release/debug)
       ├─ make: NJS modules (×2 release/debug) + njs CLI binary
       └─ dpkg-deb → nginx_1.25.5-1~bookworm+echo1_<arch>.deb

debian:bookworm-slim (runtime)
  ├─ apt-get install runtime deps (libssl3 ≥ 3.0.14 enforced)
  ├─ dpkg -i nginx_*.deb
  └─ COPY --from=upstream /docker-entrypoint.sh + /docker-entrypoint.d/

The Containerfile does NOT copy /etc/nginx from upstream. All configuration files are shipped inside the .deb and tracked by dpkg's conffile mechanism. This is required for the 10-listen-on-ipv6-by-default.sh entrypoint script, which uses dpkg-query to detect whether default.conf has been user-modified.

Integrity Guarantees

  • Source tarballs: All source archives (nginx, NJS) are SHA256-verified against hardcoded hashes before extraction. Build aborts on mismatch.
  • Build from source: ./configure && make inside a clean Debian container. No upstream binaries, no apt install nginx.
  • No network access during compilation: dependencies are installed in the builder Docker image layer; build.sh only fetches pinned source archives.

Reproducibility

The build is mostly reproducible but not hermetic:

  • nginx source version and SHA256 are pinned and verified before extraction.
  • NJS version and SHA256 are pinned and verified before extraction.
  • Builder dependencies are enumerated in Dockerfile.build but not version-pinned.
  • Debian runtime packages are resolved from live bookworm repositories at build time, so minor versions can drift between builds.

To improve reproducibility, pin the base image digest:

docker pull debian:bookworm-slim
docker inspect debian:bookworm-slim --format='{{index .RepoDigests 0}}'
# Then use: FROM debian:bookworm-slim@sha256:<digest>

CVE Remediation Details

CVE-2024-6119 - OpenSSL Version Bump

FieldValue
ComponentOpenSSL / libssl3
SeverityHigh (CVSS 7.5)
TypeDenial of Service via X.509 name checks
Baseline version3.0.11-1~deb12u2
Fixed version3.0.14-1~deb12u2 (or later)
Our version3.0.20-1~deb12u1
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-6119
Advisoryhttps://openssl-library.org/news/secadv/20240903.txt

How the fix works:

The .deb package declares Depends: libssl3 (>= 3.0.14), which forces apt-get install to pull an OpenSSL version that includes the fix. The current Debian bookworm repositories provide 3.0.20, which fixes CVE-2024-6119 and dozens of other OpenSSL CVEs from the baseline (CVE-2024-2511, CVE-2024-5535, CVE-2024-4741, CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-9143, CVE-2025-15467, CVE-2025-69420).

Download Tool