15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
20/07/2026-06:14 20/07/2026-06:15 מחשבים וטכנולוגיה Cyber Security News דיווח
A newly disclosed flaw tracked as cybersecuritynews.com
nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan
nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan
סיכום מאמר"פגם 15 שנים ב-Nginx מאפשר לתוקפים להפיל עובדים ולבצע תקיפה מרוחקת של קוד" אחד הפגמים החדשים שהתגלו ב-Nginx, המכונה "https://cybersecuritynews.com/f5-patches-multiple-nginx-vulnerabilities/", מאפשר לתוקפים להפיל עובדים ולבצע תקיפה מרוחקת של קוד. הפגם, שהתחיל להיות ניתן להפעלה סמויה מאז מרץ 2011, קשור למנוע הסקריפט של Nginx ולתמיכה בתמיכה בregex בבקשת map. מדען הביטחון, Stan, הצליח לגלות את הפגם ולהזעיק את התשובה של F5, היצרן של Nginx. החברה הוציאה תיקון לפגם, אך ישנם חששות שהפגם יכול להיות ניתן להפעלה עדיין.תוכן זה נוצר על ידי בינה מלאכותית.