Web Hack List

Preliminary research

NGINX Rift: Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability

AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from April through September. Unranked, incomplete, not community-vetted, and subject to change.

NGINX rewrite bytecode computes an escaped URI length and later copies it with stale script-engine state, creating a heap overflow when the two passes disagree. Cross-request pool grooming and a cleanup-handler overwrite turn the memory corruption into demonstrated code execution.

Record

Researcher
Zhenpeng (Leo) Lin
Published by
depthfirst
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Zhenpeng (Leo) Lin, first published at the original source. Preserved copies are kept so the citation survives its host.