PoC Archive PoC Archive

tag

Capture-Variable

  • CVE-2026-42533 web CRITICAL 9.8

    nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)

    CVE-2026-42533 is a heap buffer overflow in nginx triggered by PCRE regex capture variable handling. When two map directives share the same capture group name, a length/value mismatch occurs in the internal variable copy code (ngxhttpscriptcopycapturecode and…

    Unverified 2026-08-16