<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nginx — PoC Archive</title><link>https://poc.intelseclab.com/tags/nginx/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/nginx/index.xml" rel="self" type="application/rss+xml"/><item><title>UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34910, CVE-2026-34909, CVE-2026-34908. Status: Patched. Affects: Ubiquiti UniFi OS Server. Tags: ubiquiti, unifi, unifi-os, auth-bypass, path-traversal, command-injection, rce, unauth, kev, mirai, nginx, CVE-2026-34910.</description><category>network</category><category>Critical</category><category>ubiquiti</category><category>unifi</category><category>unifi-os</category><category>auth-bypass</category><category>path-traversal</category><category>command-injection</category><category>rce</category><category>unauth</category><category>kev</category><category>mirai</category><category>nginx</category><category>CVE-2026-34910</category></item><item><title>nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42533. Status: Patched. Affects: nginx 1.30.1 (and likely earlier versions). Tags: nginx, pcre, heap-overflow, rce, preauth, info-leak, capture-variable, map-directive, aslr-bypass, CVE-2026-42533.</description><category>web</category><category>Critical</category><category>nginx</category><category>pcre</category><category>heap-overflow</category><category>rce</category><category>preauth</category><category>info-leak</category><category>capture-variable</category><category>map-directive</category><category>aslr-bypass</category><category>CVE-2026-42533</category></item><item><title>IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974. Status: Weaponized. Affects: Kubernetes ingress-nginx admission controller. Tags: kubernetes, ingress-nginx, ingressnightmare, admission-controller, nginx, ssl-engine, shared-library-injection, cluster-secrets, docker, python, c, cwe-94.</description><category>cloud</category><category>Critical</category><category>kubernetes</category><category>ingress-nginx</category><category>ingressnightmare</category><category>admission-controller</category><category>nginx</category><category>ssl-engine</category><category>shared-library-injection</category><category>cluster-secrets</category><category>docker</category><category>python</category><category>c</category><category>cwe-94</category></item><item><title>nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40701-nginx-resolver-ocsp-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40701-nginx-resolver-ocsp-uaf/</guid><description>Medium severity (CVSS 6.3) — web · CVE-2026-40701. Status: PoC. Affects: nginx (open source). Tags: nginx, use-after-free, ocsp-stapling, resolver, memory-corruption, docker-lab, tls.</description><category>web</category><category>Medium</category><category>nginx</category><category>use-after-free</category><category>ocsp-stapling</category><category>resolver</category><category>memory-corruption</category><category>docker-lab</category><category>tls</category></item><item><title>Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</guid><description>High severity — web · CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability). Status: PoC. Affects: A custom, deliberately vulnerabilized fork of Nginx 1.25.3's QUIC transport module (ngx_event_quic_transport.c), run inside a purpose-built Docker lab — not the stock upstream Nginx release. Tags: nginx, quic, http-3, heap-overflow, dos, fuzzing, dcid, academic-lab, docker.</description><category>web</category><category>High</category><category>nginx</category><category>quic</category><category>http-3</category><category>heap-overflow</category><category>dos</category><category>fuzzing</category><category>dcid</category><category>academic-lab</category><category>docker</category></item><item><title>nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9256-nginx-poolslip-rift-rce-chain/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9256-nginx-poolslip-rift-rce-chain/</guid><description>Critical severity — web · CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift"). Status: PoC. Affects: nginx (rewrite engine). Tags: nginx, heap-overflow, heap-over-read, aslr-bypass, rce, rewrite-engine, request-smuggling-adjacent, chained-exploit.</description><category>web</category><category>Critical</category><category>nginx</category><category>heap-overflow</category><category>heap-over-read</category><category>aslr-bypass</category><category>rce</category><category>rewrite-engine</category><category>request-smuggling-adjacent</category><category>chained-exploit</category></item><item><title>NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42926-nginx-http2-frame-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42926-nginx-http2-frame-injection/</guid><description>High severity — web · CVE-2026-42926. Status: PoC. Affects: NGINX (HTTP/2 upstream proxying). Tags: nginx, http2, frame-injection, reverse-proxy, request-smuggling, docker-lab.</description><category>web</category><category>High</category><category>nginx</category><category>http2</category><category>frame-injection</category><category>reverse-proxy</category><category>request-smuggling</category><category>docker-lab</category></item><item><title>HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23813-aruba-aoscx-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-23813-aruba-aoscx-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-23813. Status: PoC. Affects: HPE Aruba Networking AOS-CX. Tags: aruba, aos-cx, authentication-bypass, nginx, ovsdb, network-switch, config-disclosure, cwe-287.</description><category>network</category><category>Critical</category><category>aruba</category><category>aos-cx</category><category>authentication-bypass</category><category>nginx</category><category>ovsdb</category><category>network-switch</category><category>config-disclosure</category><category>cwe-287</category></item><item><title>NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-14_nginx-rift-cve-2026-42945/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-14_nginx-rift-cve-2026-42945/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42945. Status: Weaponized. Affects: NGINX Open Source / NGINX Plus. Tags: RCE, unauthenticated, nginx, heap-overflow, buffer-overflow, rewrite.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>nginx</category><category>heap-overflow</category><category>buffer-overflow</category><category>rewrite</category></item></channel></rss>