Martedi 22 Settembre 2026 05:35:34 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContatti
ItalianoEnglish

#NGINX


Chiavi della cache, fiducia nascosta: perché conta una nuova tecnica per Nginx

Pubblicato: 21 Settembre 2026 12:38Categoria: Ricerca, Exploit e Sicurezza OffensivaArea: Nord America / USAAutore: DEBUGSAGE

Una tecnica di injection della chiave della cache recentemente divulgata ricorda che i livelli di prestazioni possono diventare confini di sicurezza quando la gestione delle richieste e la selezione della cache divergono.

Le cache key diventano ostili: una piccola regola di lookup con grandi conseguenze per la sicurezza

Pubblicato: 21 Settembre 2026 12:34Categoria: Ricerca, Exploit e sicurezza offensivaArea: Nord America / USAAutore: DEBUGSAGE

Una tecnica di iniezione nella cache key collegata a deploy basati su Nginx mostra come un livello di prestazioni possa trasformarsi in un percorso per aggirare i controlli di accesso, fare cache poisoning e persino portare a un possibile stored XSS.

Cinque falle in NGINX, un avvertimento critico per l'edge

Pubblicato: 03 Settembre 2026 14:40Categoria: Vulnerabilità e gestione delle patchArea: North America / USAAutore: SECURESPECTER

F5 ha rilasciato aggiornamenti di sicurezza per NGINX dopo l'identificazione di cinque vulnerabilità, un promemoria del fatto che il software posto davanti al traffico web può diventare un punto di rischio concentrato.

Quando una regex diventa ostile: la falla di memoria nel data plane di NGINX alza la posta

Pubblicato: 29 Luglio 2026 08:16Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: DEEPAUDIT

CVE-2026-42533 collega un heap overflow alla logica di espansione delle variabili di NGINX, dove uno specifico pattern di configurazione può spingere un processo worker verso un crash e, in determinate condizioni, verso l'esecuzione di codice.

Quando la logica di routing di NGINX diventa pericolosa, il raggio d'impatto inizia dalla configurazione

Pubblicato: 29 Luglio 2026 06:03Categoria: Vulnerabilità e gestione delle patchArea: North America / USAAutore: DEEPAUDIT

Un heap overflow ad alta gravità tracciato come CVE-2026-42533 mostra come le funzionalità avanzate dello stream possano diventare un rischio per la sicurezza della memoria quando variabili guidate da regex e valori complessi incontrano codice C a basso livello.

La trappola silenziosa di NGINX: un overflow critico nascosto dietro un raro pattern di configurazione

Pubblicato: 20 Luglio 2026 16:37Categoria: Vulnerabilità e gestione delle patchArea: North America / USAAutore: DEEPAUDIT

Un heap overflow in NGINX conta meno per il fatto di esistere ovunque, e più perché il percorso pericoloso può essere nascosto dentro una mappa regex apparentemente normale.

Patch, Probe, Repeat: F5 Fixes Bugs in the Traffic Layer That Sits Between Users and Everything Else

Published: 16 July 2026 12:18Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Multiple flaws in BIG-IP and NGINX matter less because of the product names than because of where they live: inline, in the request path, where a small defect can become a large operational problem.

Three NGINX Flaws, One Quiet Weak Spot: When Request Processing Starts to Crack

Published: 16 July 2026 10:24Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A small cluster of memory-safety bugs in NGINX shows how edge software can shift from traffic handler to attack surface when specific modules are in play.

Inside the Proxy Layer: NGINX’s New Patch Cycle Shows How Small Bugs Can Touch Big Traffic Paths

Published: 16 July 2026 08:03Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

F5 has disclosed three NGINX vulnerabilities, including one critical issue that could lead to remote code execution on hardened-dependent systems, while the other flaws point to memory leaks and denial-of-service risk.

When a QUIC Bug Meets a Memory-Safety Wall, the Patch Still Wins

Published: 19 June 2026 10:41Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CVE-2026-42530 is a critical NGINX HTTP/3 flaw where ASLR may affect exploitability, but not the urgency of fixing the bug itself.

NGINX Patch Wave Exposes the Fragile Center of Modern Traffic Control

Published: 18 June 2026 19:31Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

F5’s emergency fix cycle puts reverse proxies, ingress controllers, and gateway stacks back in the spotlight, where a single flaw can become a platform-wide problem.

Edge Server Alarm Bells: NGINX Flaws Put Configuration Under the Microscope

Published: 18 June 2026 19:26Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

An out-of-band vendor warning over multiple NGINX vulnerabilities shows why patching matters, but also why module choices and deployment layout can shape real-world risk.

Two High-Severity NGINX Flaws Put Patch Discipline Back on the Front Line

Published: 18 June 2026 18:18Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

An Italian CSIRT bulletin on resolved NGINX vulnerabilities is a reminder that edge software is only as safe as the exact build, modules, and configuration running in production.

Emergency NGINX Patches Put Edge Servers on the Clock

Published: 18 June 2026 15:32Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

F5 has pushed urgent fixes for multiple NGINX flaws, including two critical issues that could let an attacker run code on vulnerable systems.

NGINX Patches Expose a Fragile Edge: When Config Becomes the Attack Surface

Published: 18 June 2026 12:26Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Fresh critical and high-severity NGINX fixes show how a few rewrite and proxy directives can turn an internet-facing layer into a crash point, and in narrower conditions, a path toward code execution.

HTTP/2’s Speed Layer Becomes a Memory Trap

Published: 04 June 2026 16:33Category: Vulnerabilities & Patch ManagementAuthor: SECURESPECTER

A newly described remote denial-of-service pattern shows how header compression and connection retention can turn HTTP/2 into a resource-exhaustion problem for major web stacks.

HTTP/2’s Speed Trap: A Remote DoS Warning for Web Servers at the Edge

Published: 03 June 2026 12:53Category: Vulnerabilities & Patch ManagementAuthor: DEEPAUDIT

A reported “HTTP/2 Bomb” issue puts availability back in the spotlight, showing how default HTTP/2 handling can become a pressure point for major web servers and proxies.

HTTP/2 Bomb Raises a New Availability Alarm for Major Server Stacks

Published: 03 June 2026 12:50Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

A newly disclosed HTTP/2 issue may enable remote denial-of-service conditions against nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora.

HTTP/2 Bomb Puts Memory Pressure Back on the Defensive Map

Published: 03 June 2026 12:46Category: Research, Exploits & Offensive SecurityAuthor: DEBUGSAGE

A new exploit label is drawing attention to a familiar problem: HTTP/2 efficiency features can become resource-pressure points when limits are too loose.

NGINX Rewrite Logic Turns a Routine Feature into a Crash and Code-Execution Risk

Published: 25 May 2026 08:17Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CVE-2026-9256 sits in a narrow but dangerous corner of NGINX: rewrite rules that reuse overlapping PCRE captures can push a worker into denial of service and, under added conditions, into remote code execution.