A second remotely exploitable vulnerability in nginx has been identified in just 10 days

Corrective releases nginx 1.31.1 and 1.30.2 have been issued to address a critical vulnerability (CVE-2026-9256) that allows remote code execution with the privileges of the nginx worker process through the sending of specially crafted HTTP requests. The researchers who identified the issue demonstrated a working exploit, which will be published along with a complete description 30 days after the patch. The vulnerability has been given the codename nginx-poolslip. The issue has existed since version nginx 0.1.17. As of the time of this news, patches for angie and freenginx have not been released.

Like the similar issue resolved last week, the new vulnerability is caused by a buffer overflow in the ngx_http_rewrite_module and is manifested in configurations with certain regular expressions in the 'rewrite' directive. In this case, the vulnerability affects systems with overlapping patterns for substitution (parentheses within parentheses) in the rewrite expression, such as '^/((.*))$' or '^/(test([123]))$', when used together with multiple unnamed substitutions in the replacement string (e.g., '$1$2').

Additionally, the release of njs 0.9.9, a module for integrating JavaScript interpreters into the nginx HTTP server, can be noted. The new version fixes a vulnerability (CVE-2026-8711), which has been present since version njs 0.9.4. The issue is caused by a buffer overflow and is noticed in configurations with the js_fetch_proxy directive containing nginx variables with data from the client request (e.g., $http_*, $arg_*, and $cookie_*), combined with the use of a location handler that calls the ngx.fetch() function. This vulnerability can be exploited for code execution with the privileges of the nginx worker process through specially crafted HTTP requests.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster