Skip to finding
important · Research — edge

New public exploit code turns nginx's capture-clobbering bug into pre-authentication code execution with ASLR enabled.

Affects

nginx Open Source and NGINX Plus web, reverse-proxy and stream servers on affected configurations.

The attack applies only when a configuration evaluates a regex capture before an attacker-influenced regex map variable in the same two-pass buffer; we do not know how common that pattern is.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026