Nginx Stream Rift Unauthenticated Remote Code Execution Exploit

This module exploits the nginx stream ssl_preread/SNI variant of CVE-2026-42533. A crafted TLS Server Name Indication triggers two-pass complex-value evaluation, allowing an unauthenticated attacker to disclose process addresses and corrupt the nginx worker heap. The module captures the leaked addresses, sprays a forged cleanup handler through the HTTP listener, and triggers the corruption through the stream listener to invoke system() in the nginx worker. It then downloads and executes a Core Impact Linux agent. The attack is layout-dependent and may interrupt the nginx worker. The deployed Core Impact agent runs with the privileges of the nginx worker account.
Exploit Platform
Product Name