CVE-2026-9256Disclosure(debian / debian_linux)

CRITICALCVSS 9.2 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • discovery
  • dos
  • enterprise_linux

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 45 mentions across 19 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 28 signals
  • Disclosure: 18 classified signals
  • General: 9 classified signals
  • Peaked 17d ago at 6 mentions (2026-05-23); latest day: 1
  • 45 total mentions across 19 days

Affected systems

Products
debian_linuxdiscoverydosenterprise_linuxhardened_imagesnginx_gateway_fabricnginx_ingress_controllernginx_instance_managernginx_open_sourcenginx_plus

10 versions affected across 12 products

Deep dive

Activity timeline45 mentions / 19d
02356Mentions · 2026-05-22: 5Mentions · 2026-05-23: 6Mentions · 2026-05-24: 4Mentions · 2026-05-25: 6Mentions · 2026-05-26: 5Mentions · 2026-05-27: 1Mentions · 2026-05-29: 2Mentions · 2026-05-31: 1Mentions · 2026-06-01: 1Mentions · 2026-06-03: 1Mentions · 2026-06-04: 1Mentions · 2026-06-07: 2Mentions · 2026-06-08: 3Mentions · 2026-06-09: 2Mentions · 2026-06-15: 1Mentions · 2026-07-19: 1Mentions · 2026-07-23: 1Mentions · 2026-07-27: 1Mentions · 2026-08-31: 1PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-26: 2PoC Mentioned / Linked · 2026-05-29: 1PoC Mentioned / Linked · 2026-05-31: 1PoC Mentioned / Linked · 2026-06-15: 1Exploit Tool / Code · 2026-05-23: 1Exploit Tool / Code · 2026-05-29: 1Active Exploitation · 2026-05-23: 2Active Exploitation · 2026-07-19: 1Patch / Workaround · 2026-05-22: 3Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-25: 4Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-08: 2Technical Details · 2026-05-22: 2Technical Details · 2026-05-23: 4Technical Details · 2026-05-24: 2Technical Details · 2026-05-25: 5Technical Details · 2026-05-26: 4Technical Details · 2026-05-29: 2Technical Details · 2026-05-31: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-08: 3Technical Details · 2026-06-09: 1Technical Details · 2026-06-15: 1Technical Details · 2026-08-31: 105-2205-2305-2405-2505-2605-2705-2905-3106-0106-0306-0406-0706-0806-0906-1507-1907-2307-2708-31
Signal classification5 categories
Disclosure
1840.0%
Patch
1226.7%
General
920.0%
Active Exploitation
36.7%
PoC
36.7%
Referenced assets29 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-225
Disclosure2Patch3
2026-05-236
Active Exploitation2Disclosure2Patch1PoC1
2026-05-244
Disclosure1General2Patch1
2026-05-256
Disclosure4Patch2
2026-05-265
Disclosure4Patch1
2026-05-271
Patch1
2026-05-292
Patch1PoC1
2026-05-311
Disclosure1
2026-06-011
Patch1
2026-06-031
General1
2026-06-041
General1
2026-06-072
General2
2026-06-083
Disclosure2Patch1
2026-06-092
Disclosure1General1
2026-06-151
PoC1
2026-07-191
Active Exploitation1
2026-07-231
General1
2026-07-271
Disclosure1
2026-08-311
General1
Full discourse20 posts
  • Md Ismail Šojal 🕷️@0x0SojalSec
    General

    FULL REMOTE CODE EXECUTION on default nginx 1.30.0 no config changes needed. 🫠 Verichains a deadly exploit chain combining Nginx-Rift (CVE-2026-42945) + Nginx-PoolSlip (CVE-2026-9256). 2-byte heap pointer overwrite & heap over-read then ASLR bypass to arbitrary command execution via system() on connection teardown.

    Post summary

    The post highlights a full remote code execution chain that combines CVE-2026-42945 and CVE-2026-9256, detailing a 2‑byte heap pointer overwrite, heap over‑read, ASLR bypass, and execution of system() during connection teardown, but it provides no PoC, exploit code, or evidence of active exploitation.

    51174884617118.8K
    49.9K followersView on X
  • Aretiq.AI@AretiqAI
    Disclosure

    CVE-2026-9256 — NGINX heap buffer overflow (CVSS 9.2 Critical) Overlapping PCRE captures in rewrite → heap overflow + heap info leak. Unauthenticated, remote. DoS + RCE path confirmed. Fixed: nginx 1.31.1 / 1.30.2 https://aretiq.ai/research/vul260525-cve-2026-9256-nginx-ngx-http-rewrite-module-overlapping-pcre-captures-heap-buffer-overflow-rce/

    Post summary

    A critical heap buffer overflow in NGINX’s rewrite module permits remote DoS and RCE; the issue is fixed in nginx 1.31.1/1.30.2, with the research link providing further vulnerability details.

    03231377413.3K
    195 followersView on X
  • mufeed vh@mufeedvh
    Disclosure

    Introducing ENDGINX - 5 CVEs in NGINX with open models. We let loose GLM 5.1 and 5.2 by @Zai_org on the NGINX codebase. The work resulted in six fixed vulnerabilities across five CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, and CVE-2026-42533. First of our open-model vulnerability research series. https://winfunc.com/research/endginx

    Post summary

    The tweet announces five new CVEs discovered in NGINX, revealing the research effort and listing the affected identifiers, but it offers no PoC, exploitation details, or patch information.

    130192549.2K
    4.8K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad Nginx-poolslip permite DoS y ejecución de código Se ha revelado una vulnerabilidad denominada nginx-poolslip (CVE-2026-9256) que afecta tanto a NGINX Plus como a NGINX Open Source https://blog.elhacker.net/2026/05/vulnerabilidad-nginx-poolslip-permite.html

    Post summary

    The article discloses a new CVE‑2026‑9256 vulnerability in NGINX, which enables Denial‑of‑Service and code execution on both NGINX Plus and Open Source editions.

    016052143.3K
    140.9K followersView on X
  • Frank@jedisct1
    Patch

    nginx 1.31.1 released to fix CVE-2026-9256 https://nginx.org

    Post summary

    Nginx has released version 1.31.1 to address CVE-2026-9256, providing a patch to mitigate the vulnerability.

    3203263.3K
    17.5K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-9256 — NGINX ngx_http_rewrite_module Overlapping PCRE Captures Heap Buffer Overflow RCE https://aretiq.ai/research/vul260525-cve-2026-9256-nginx-ngx-http-rewrite-module-overlapping-pcre-captures-heap-buffer-overflow-rce/

    Post summary

    The text announces a new heap buffer overflow vulnerability (CVE-2026-9256) in NGINX's ngx_http_rewrite_module that allows remote code execution, referencing an external research document for details.

    0401592.5K
    158.6K followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    Aretiq's report [https://aretiq.ai/research/vul260525-cve-2026-9256-nginx-ngx-http-rewrite-module-overlapping-pcre-captures-heap-buffer-overflow-rce/] demonstrating a heap-leak primitive, possible similar as @nebusecurity 's (full RCE nginx teaser). Freenginx is already patching the case as of yesterday. Still hitting a wall there but it might be possible to achieve RCE on nginx under very specific configuration. Patch on freenginx under 6523dbe

    Post summary

    The report highlights a heap‑buffer‐overflow RCE in nginx and notes that Freenginx has issued an update, providing both technical details and a patch reference.

    010862.2K
    158.6K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-9256 PT ID: PT-2026-42776 Vendor: F5 Product: NGINX Plus Description: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Link: https://github.com/W5M1n9/Self-Researched-POC #dbugs_vuln

    Post summary

    A PoC and exploit for CVE‑2026‑9256 has been released, demonstrating how a regex‑based rewrite bug in NGINX can trigger a heap buffer overflow, with a GitHub repository containing working evidence, though no active exploitation or patch is reported.

    01055974
    2.6K followersView on X
  • OpenResty@OpenResty
    Patch

    OpenResty 1.29.2.5 is now officially released! Key update: backported the official Nginx security patch to fix a buffer overflow vulnerability in `ngx_http_rewrite_module` (CVE-2026-9256), further strengthening security protection. Related links in the comments. #OpenResty #WebServer #Nginx

    Post summary

    OpenResty 1.29.2.5 includes a patch that backports the official Nginx security fix for CVE-2026-9256, addressing a buffer overflow in the ngx_http_rewrite_module.

    12031618
    1.6K followersView on X
  • Migel Tissera@migtissera
    PoC

    Hey guys, I introduced @drost_ai last week. Here's Drost's first receipt: it independently rediscovered nginx-poolslip (CVE-2026-9256). Drost read the source, built nginx with ASAN, triggered the heap overflow, and proved it. Not a new CVE, but a known-answer validation (with receipts). https://www.drost.ai/research/drost-nginx-poolslip

    Post summary

    The post confirms that Drost AI independently reproduced a known Nginx heap overflow (CVE-2026-9256) using ASAN, providing proof and a receipt link, but does not mention active exploitation, patches, or exploits.

    00040194
    4.7K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🚨 NGINX sürümleriniz güncel değilse güncelleyin; Rift (CVE-2026-42945) güvenlik açığı 1.30.0 ve öncesini etkiliyor. PoolSlip (CVE-2026-9256) güvenlik açığı 1.31.0 ve öncesini etkiliyor. Patchlenmiş sürümler: Nginx Open Source için 1.30.2 (stable) ya da 1.31.1 (mainline).

    Post summary

    The note warns that NGINX versions 1.30.0 and earlier are vulnerable to CVE-2026-42945 and versions 1.31.0 and earlier to CVE-2026-9256, and recommends updating to the patched releases 1.30.2 or 1.31.1.

    00030306
    1.4K followersView on X
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.63 is now available:   • ea-nginx → 1.31.1 • Listed CVE-2026-9256 (nginx-poolslip) • ea-nginx-passenger → 6.1.3 Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache #cPanelUpdates https://t.co/oz7etncxnh

    Post summary

    EasyApache 4 v25.63 releases updated nginx (1.31.1) to address CVE‑2026‑9256 (nginx‑poolslip), providing a patch for the vulnerability.

    00030331
    28.8K followersView on X
  • Sami Laiho@samilaiho
    Disclosure

    NGINX Plus and NGINX Open Source have a vulnerability in... · CVE-2026-9256 · GitHub Advisory Database · GitHub https://github.com/advisories/GHSA-h78r-86c6-jgp4

    Post summary

    A new vulnerability (CVE-2026-9256) affecting NGINX Plus and NGINX Open Source has been disclosed, with reference to a GitHub advisory, but no further details on exploits, patches, or technical specifics are provided.

    01011820
    30.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『The confirmed heap pointer leak provides heap ASLR bypass, but PIE and full RELRO on modern distributions require a secondary leak』 CVE-2026-9256 — NGINX ngx_http_rewrite_module Overlapping PCRE Captures Heap Buffer Overflow RCE https://aretiq.ai/research/vul260525-cve-2026-9256-nginx-ngx-http-rewrite-module-overlapping-pcre-captures-heap-buffer-overflow-rce/

    Post summary

    The brief describes the technical aspects of CVE‑2026‑9256, highlighting a heap pointer leak leading to a heap buffer overflow RCE, and provides a link to a research page but does not mention active exploitation or a usable PoC.

    01011664
    6.9K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-9256: NGINX: ngx_http_rewrite_module buffer overflow https://www.openwall.com/lists/oss-security/2026/05/22/14 Similarly to CVE-2026-42945 aka NGINX Rift, certain rewrite directives in the configuration let unauthenticated attackers crash worker processes or execute remote code via crafted HTTP requests

    Post summary

    The note discloses a buffer overflow in NGINX’s rewrite module (CVE‑2026‑9256) that allows unauthenticated attackers to crash worker processes or achieve remote code execution with crafted HTTP requests, but no PoC, exploit, or mitigation information is provided.

    01011821
    4.6K followersView on X
  • Movable Type@movabletype
    Patch

    Nginx における脆弱性 CVE-2026-9256(nginx-poolslip)への対応について、Movable Type クラウド版では、WebサーバーにNginxを使用中のすべてのお客様の環境で対応が完了しています。引き続き安心してご利用ください。 詳細はニュースをご覧ください。 https://www.sixapart.jp/movabletype/news/2026/05/25-1000.html

    Post summary

    Movable Type Cloud has completed patching all customers using Nginx for CVE-2026-9256 and directs users to a news article for details.

    02000413
    764 followersView on X
  • 月0PVから始めたエンジニア@0pv_engineer
    General

    自宅ホームルーターでWebサービス運営してる話。 構成: Cloudflare Tunnel → nginx → Django 自宅IPは隠蔽・サーバー代0円。 今日nginxの脆弱性(CVE-2026-9256)が公開されて緊急対応しました。 自宅PCへの攻撃怖くてヒヤヒヤする😇 #個人開発 #nginx #自宅サーバー

    Post summary

    The user reports the announcement of nginx CVE-2026-9256 and their urgent reaction, but provides no further technical details or evidence of exploitation.

    0002018
    44 followersView on X
  • Joshua Rogers@MegaManSec
    PoC

    curl -v "http://TARGET/$(python3 -c "print('+'*500, end='')")" nice test for CVE-2026-9256 aka nginx-poolslip

    Post summary

    A simple curl command is used to demonstrate exploitation of CVE-2026-9256 (nginx-poolslip), serving as a proof‑of‑concept but lacking broader exploit details or mitigation information.

    00020205
    791 followersView on X
  • Hshh@UnrealHshh
    Patch

    nginx-1.30.2 stable and nginx-1.31.1 mainline versions have been released, with a fix for buffer overflow vulnerability in the ngx_http_rewrite_module (CVE-2026-9256). 又到了升级时间

    Post summary

    The bulletin announces new nginx releases that fix CVE‑2026‑9256, a buffer overflow in the rewrite module, encouraging users to upgrade.

    00020222
    246 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for F5 NGINX Plus and NGINX Open Source (CVE-2026-9256) https://vuldb.com/vuln/365202

    Post summary

    A new vulnerability with increased severity for F5 NGINX Plus and NGINX Open Source (CVE-2026-9256) has been disclosed, but no further details or mitigations are provided.

    00020163
    2.3K followersView on X
CPE platform detail29 entries

29 of 29 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Appf5dos-nginx-
Appf5dos4.9.0nginx-
Appf5nginx_gateway_fabric---
Appf5nginx_ingress_controller---
Appf5nginx_instance_manager---
Appf5nginx_open_source---
Appf5nginx_open_source1.31.0--
Appf5nginx_plus---
Appf5nginx_plus37.0.0.1--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5waf-nginx-
Appredhatdiscovery---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---
Appredhatupdate_infrastructure---

Explore more