ExLisper Site
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Eager Eagle@lemmy.world to Selfhosted@lemmy.worldEnglish ·
edit-2
1 month ago

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

thehackernews.com

external-link
message-square
14
link
fedilink
110
external-link

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

thehackernews.com

Eager Eagle@lemmy.world to Selfhosted@lemmy.worldEnglish ·
edit-2
1 month ago
message-square
14
link
fedilink
NGINX Rift CVE-2026-42945 scores 9.2 after 18 years, enabling unauthenticated RCE or DoS via crafted HTTP requests.

Update your nginx instances

cross-posted from: https://lemmy.world/post/46851448

  • Affected an non-affected versions https://nginx.org/en/security_advisories.html
  • CVE record https://www.cve.org/CVERecord?id=CVE-2026-42945
  • CVE details https://nvd.nist.gov/vuln/detail/CVE-2026-42945
  • PoC https://github.com/DepthFirstDisclosures/Nginx-Rift

CVE - Common Vulnerabilities and Exposures system
RCE - Remote Code Execution
PoC - Proof of Concept

  • skankhunt42@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 month ago

    Yep. I wasn’t affected thankfully. Didn’t realise I was flexing, sorry. Just happy most of my stack is automated and it’s quite low maintenance at this point.

    Where do I draw the line then? Serious question. If updating every couple hours is bad, then what’s safe?

    • GreenKnight23@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 month ago

      for corporate services we do every 30 days. which is standard. emergency patches get direct support and resolved quickly.

    • JaddedFauceet@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      idk, also it is not about the frequency you update, it is usually about how long has it been since package is published to the internet

      see concept of min release age https://pnpm.io/blog/releases/10.16

      i wonder if other package manager have similar thing or not

    • Pinhead77@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      27 days ago

      You can use pnpm instead of npm. pnpm has a “Delay dependency updates” feature where you can install package versions that are x old only.
      See https://pnpm.io/supply-chain-security#delay-dependency-updates

      Edit: I just found out, that this can also be specified in npm and yarn: https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e93104

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam.

  3. Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.

  4. Don’t duplicate the full text of your blog or git here. Just post the link for folks to click.

  5. Submission headline should match the article title.

  6. No trolling.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 385 users / day
  • 2.04K users / week
  • 6.51K users / month
  • 8.56K users / 6 months
  • 1 local subscriber
  • 59.9K subscribers
  • 681 Posts
  • 7.93K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • ayyy@sh.itjust.works
  • curbstickle_lw@lemmy.world
  • BE: 0.19.16
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org