July 25, 2026 at 01:52PM

■■■■□ Open-sourcing RCE implementation for CVE-2026-42533

This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!).

F5 released the security advisory a week ago on July 15th. Fun fact: this bug appears to have been found concurrently by multiple groups. Our team at @depthfirstlabs caught it using our internal systems, right alongside CVE-2026-42530, a separate issue in NGINX’s HTTP/3 QPACK implementation.

https://x.com/i/status/2080832510838337940