■■■■□ Open-sourcing RCE implementation for CVE-2026-42533
This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!).
F5 released the security advisory a week ago on July 15th. Fun fact: this bug appears to have been found concurrently by multiple groups. Our team at @depthfirstlabs caught it using our internal systems, right alongside CVE-2026-42530, a separate issue in NGINX’s HTTP/3 QPACK implementation.
https://x.com/i/status/2080832510838337940
