Zhenpeng (Leo) Lin (@Markak_) on X

X (formerly Twitter) ·

1 min read Original article ↗

NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in

@nginx

impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at depthfirst.com/nginx-rift