Cloud Engineer | Security enthusiast & researcher | Developer
- Tomorrow: ASLR for CVE-2026-42945 can be bypassed by having a host access primitive.. Jokes aside, still an interesting PoCHere's the PoC for Nginx CVE-2026-42945 which works against vanilla Ubuntu (and any other distro?) + Nginx with ASLR enabled. I have included all iterations of the PoC the LLM was kicked to improve. TL;DR: We can use an LFI/file-read primitive to leak enough details from
- Don't disable ASLRNGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at
- It's the Friday deployment time over at Discord
- Hard to patch if there's no patch. It's a 0day, and thank you for that. Blocking the module has some more side-effects than the ones described, see openwall.com/lists/oss-secu… I call that irresponsible disclosure, change my mind.Patch your Linux boxes! Copy.Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms. Found by the teams at @theori_io and @xint_official More





