A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of the argument wans.policy.list1 results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
[POC] CVE-2026-42530 — CVE-2026-42530
Scanner PoC for CVE-2026-42530 -- nginx 1.31.0-1.31.1 HTTP/3 QPACK encoder stream Use-After-Free (CVSS 9.2)
[POC] CVE-2026-42533 — CVE-2026-42533
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
[POC] GHSA-652q-gvq3-74qv — CVE-2026-42533-nginx
CVE-2026-42533 Nginx
[POC] CVE-2026-42533 — CVE-2026-42533-
Vulnerabilidad en NGINX
[POC] CVE-2026-42533 — CVE-2026-42533
Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow
[POC] CVE-2026-42533 — ghostlock-vagrant-box
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
[POC] CVE-2026-42533 — nginx-map-risk-audit
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
[POC] CVE-2026-42533 — CVE-2026-42533-Scanner
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-4253-Scanner
Non-destructive vulnerability scanner for NGINX HTTP/3 (ngx_http_v3_module). It ONLY performs a safe probe: opens an HTTP/3 (QUIC) connection, sends a single HEAD request and inspects the `Server` response header. It NEVER attempts to reopen a QPACK encoder stream or trigger the use-after-free.
[POC] CVE-2026-42530 — CVE-2026-42530
CVE-2026-42530
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free