Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-42945 — Full CVE-2026-42945 research repository with heap buffer overflow analysis, RCE exploit (heap spray + Feng Shui), detection scripts, and patching guidance for NGINX rewrite module vulnerability. | Kitploit
Tools/GitHubGitHub/quantumworld-dpdns-io/cve-2026-42945
Vulnerability AnalysisExploitationWeb SecurityFuzzingPenetration TestingLearning & EducationIncident ResponseBinary ExploitationLabs & Practice
GitHubquantumworld-dpdns-io/cve-2026-42945

CVE-2026-42945

Full CVE-2026-42945 research repository with heap buffer overflow analysis, RCE exploit (heap spray + Feng Shui), detection scripts, and patching guidance for NGINX rewrite module vulnerability.

View Repository
134 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Screenshot 2026-05-28 at 4 09 53 PM

CVE-2026-42945 — NGINX Rift

Heap Buffer Overflow in NGINX ngx_http_rewrite_module

MetricValue
CVSS v4.09.2 (Critical)
CVSS v3.18.1 (High) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE122 — Heap-based Buffer Overflow
IntroducedJune 2008 — v0.6.27
DiscoveredApril 2026 — DepthFirst Research
FixedMay 13, 2026 — v1.30.1, v1.31.0
CVE PublishedMay 21, 2026
Lifetime~18 years (undetected)
Fix Commit524977e7c534e87e5b55739fa74601c9f1102686

Table of Contents

  1. Vulnerability Summary
  2. Root Cause Analysis
  3. Exploitation Mechanics
  4. Fix Analysis
  5. Affected Versions
  6. Detection
  7. Mitigation
  8. Project Structure
  9. Quick Start
  10. Build & Run Vulnerable
  11. Trigger the Overflow
  12. RCE Exploit
  13. Reverse Shell Verification
  14. Patching
  15. Testing
  16. Fuzzing
  17. CI Pipeline
  18. Documentation Index
  19. Project Statistics
  20. References

1. Vulnerability Summary

An unauthenticated, remote attacker can trigger a deterministic heap buffer overflow in NGINX worker processes by sending a crafted HTTP request to a server with a specific rewrite + set/if/rewrite configuration pattern. The overflow corrupts heap metadata (ngx_pool_cleanup_t pointers), enabling Remote Code Execution (RCE) via heap spray and Feng Shui techniques.

Trigger Pattern

server {
    listen 19321;

    location ~ ^/api/(.*)$ {
        rewrite ^/api/(.*)$ /internal?migrated=true;
        set $original_endpoint $1;
    }
}

Key requirements:

  • A rewrite directive whose replacement contains ? (query-string separator)
  • A subsequent set, if, or rewrite directive that references an unnamed PCRE capture ($1, $2, etc.)
  • The ? in the rewrite replacement triggers ngx_http_script_start_args_code which sets e->is_args = 1

What an attacker can achieve

CapabilityDescription
Denial of ServiceCrash worker processes deterministically, causing respawn loops (works regardless of ASLR)
Remote Code ExecutionWith ASLR disabled (or bypassed via partial overwrite), achieve full RCE as the nginx user
Data ExfiltrationThrough memory read primitives, extract sensitive data from worker heap
PersistencePlant backdoors via code execution in worker process memory

2. Root Cause Analysis

The Two-Pass Script Engine

NGINX's ngx_http_rewrite_module uses a two-pass script engine in src/http/ngx_http_script.c:

  1. Length Pass (ngx_http_script_run): iterates all script codes to compute the total buffer size needed. Writes lengths to le.ip and le.pos.
  2. Copy Pass (ngx_http_script_copy_len/_code): iterates again, writing actual bytes into the pre-allocated buffer at e->ip and e->pos.

Each script code has two handlers: one for each pass. For example:

  • ngx_http_script_copy_len → ngx_http_script_copy_code
  • ngx_http_script_start_args_len → ngx_http_script_start_args_code

The is_args Flag

The flag e->is_args on the engine structure (ngx_http_script_engine_t) controls how the copy pass handles certain characters:

typedef struct {
    u_char                  *ip;
    u_char                  *pos;
    ngx_http_variable_value_t *sp;
    ngx_str_t               buf;
    int                     flushed;
    unsigned                is_args:1;    // <-- THE BUG
    unsigned                ncaptures:1;
    ngx_uint_t              captures_size;
    // ...
} ngx_http_script_engine_t;

When e->is_args = 1, the copy-code for $N capture references calls ngx_escape_uri() with NGX_ESCAPE_ARGS, which expands:

  • + → %2B (1 byte → 3 bytes, +200%)
  • % → %25 (1 byte → 3 bytes, +200%)
  • & → %26 (1 byte → 3 bytes, +200%)

The Bug: Flag Leak Across Passes

The execution flow for the vulnerable pattern:

rewrite ^/api/(.*)$ /internal?migrated=true;
  1. During the rewrite evaluation, the engine encounters ? in the replacement string, which triggers ngx_http_script_start_args_code, setting e->is_args = 1.
  2. The rewrite modifies the request URI and then continues to the next directive.
  3. e->is_args is NEVER CLEARED.

Then:

set $original_endpoint $1;
  1. A fresh sub-engine (le) is created for the length pass:

    ngx_memzero(&le, sizeof(ngx_http_script_engine_t));
    

    This correctly zeroes le.is_args = 0, so the length pass returns the raw, unescaped capture length.

  2. The copy pass reuses the main engine e, which still has e->is_args = 1 from step 1. The copy pass applies URI-escaping, expanding each escapable character from 1 byte to 3 bytes inside a buffer that was sized for the raw length — heap overflow.

Visual Walkthrough

Pass 1 (Length — sub-engine le):
  le.is_args = 0
  capture $1 = "A+++++B" → length = 7

Buffer allocated: 7 bytes

Pass 2 (Copy — main engine e):
  e.is_args = 1  ← LEAKED from rewrite
  capture $1 = "A+++++B"
  ngx_escape_uri("A+++++B", NGX_ESCAPE_ARGS):
    A → A        (1 byte)
    + → %2B      (3 bytes) ← EXPANSION
    + → %2B      (3 bytes)
    + → %2B      (3 bytes)
    + → %2B      (3 bytes)
    + → %2B      (3 bytes)
    B → B        (1 byte)
  total written: 17 bytes
  buffer size:    7 bytes
  OVERFLOW:      10 bytes

The expansion ratio is 7 + (n_escapable * 2) where n_escapable is the count of +, %, and & in the capture.


3. Exploitation Mechanics

Overview

StepTechniqueDescription
1OverflowSend crafted URI with + padding to overflow heap buffer
2Heap SprayPOST large bodies to /spray to fill heap with controlled data
3Feng ShuiArrange allocations so overflow target (ngx_pool_cleanup_t) is adjacent
4Corrupt HandlerOverflow overwrites ngx_pool_cleanup_t.handler with system() address
5Trigger CleanupWait for pool destruction → system(cmd) executes attacker command
6Reverse ShellChain to reverse shell payload for interactive access

Cross-Request Feng Shui

Single-request Feng Shui fails because the overflow corrupts the pool's metadata (->d.next, ->d.failed) before reaching the cleanup pointer. When the pool is destroyed at request end, the corrupted metadata causes a crash before system() is called.

Instead, the exploit uses cross-request Feng Shui:

  1. Request 1 (spray): POST large body to /spray. The backend (server.py) holds the response with X-Delay header, keeping the connection open and preserving the heap allocation. The spray fills the heap with fake ngx_pool_cleanup_t blocks.
  2. Request 2 (overflow): Send the overflow URI. The overflow corrupts only the cleanup pointer (not pool metadata), pointing it to the sprayed fake block.
  3. Pool destruction: When the spray response completes (delay expires), the pool's cleanup chain walks to the fake block and calls system(cmd).

Address Requirements

Download Tool