<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #NGINX</title><description>Cybersecurity articles tagged #NGINX on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-42533: NGINX RCE and Denial of Service — Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-42533-nginx-rce-and-denial-of-service-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42533-nginx-rce-and-denial-of-service-mitigation-guide</guid><description>Exploit analysis of CVE-2026-42533, a critical heap buffer overflow in NGINX. Learn how to detect and patch worker process crashes and potential RCE.</description><pubDate>Mon, 20 Jul 2026 03:26:34 GMT</pubDate><category>CVE-2026-42533</category><category>NGINX</category><category>RCE</category><category>Heap Overflow</category><category>F5</category><category>Vulnerability</category></item><item><title>CVE-2026-42530 &amp; -42531: NGINX RCE via Use-After-Free</title><link>https://runtimerebel.com/blog/cve-2026-42530-42531-nginx-rce-via-use-after-free</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42530-42531-nginx-rce-via-use-after-free</guid><description>F5 addresses critical RCE flaws [CVE-2026-42530, CVE-2026-42531] in NGINX Open Source. Unauthenticated attackers can exploit use-after-free issues. Patch now.</description><pubDate>Thu, 18 Jun 2026 20:54:37 GMT</pubDate><category>NGINX</category><category>F5</category><category>RCE</category><category>CVE-2026-42530</category><category>CVE-2026-42531</category><category>Use After Free</category><category>HTTP 3</category><category>HTTP 2</category></item><item><title>HTTP/2 Bomb: Remote DoS Affects NGINX, Apache, and Microsoft IIS</title><link>https://runtimerebel.com/blog/http-2-bomb-remote-dos-affects-nginx-apache-and-microsoft-iis</link><guid isPermaLink="true">https://runtimerebel.com/blog/http-2-bomb-remote-dos-affects-nginx-apache-and-microsoft-iis</guid><description>Researchers identify HTTP/2 Bomb vulnerability affecting NGINX, Apache, and IIS default settings, allowing remote denial-of-service attacks on web servers.</description><pubDate>Wed, 03 Jun 2026 09:43:56 GMT</pubDate><category>HTTP 2 Bomb</category><category>NGINX</category><category>Apache HTTPD</category><category>Microsoft IIS</category><category>Denial of Service</category></item><item><title>CVE-2024-31079: Critical NGINX RCE Vulnerability Exploitation</title><link>https://runtimerebel.com/blog/cve-2024-31079-critical-nginx-rce-vulnerability-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-31079-critical-nginx-rce-vulnerability-exploitation</guid><description>Active exploitation of CVE-2024-31079 in the NGINX HTTP/3 module allows for RCE and DoS. Security teams must patch NGINX Open Source and Plus immediately.</description><pubDate>Mon, 18 May 2026 09:21:13 GMT</pubDate><category>CVE-2024-31079</category><category>NGINX</category><category>RCE</category><category>HTTP 3</category><category>F5</category></item><item><title>NGINX CVE-2026-42945: Heap Buffer Overflow Exploited — Patch Now</title><link>https://runtimerebel.com/blog/nginx-cve-2026-42945-heap-buffer-overflow-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/nginx-cve-2026-42945-heap-buffer-overflow-exploited-patch-now</guid><description>Active exploitation of CVE-2026-42945 in NGINX ngx_http_rewrite_module allows for worker process crashes and remote code execution. Update to version 1.31.0.</description><pubDate>Sun, 17 May 2026 16:25:03 GMT</pubDate><category>CVE-2026-42945</category><category>NGINX</category><category>RCE</category><category>Heap Buffer Overflow</category></item><item><title>NGINX HTTP/3 RCE via CVE-2024-24989 — Mitigation Guide</title><link>https://runtimerebel.com/blog/nginx-http-3-rce-via-cve-2024-24989-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/nginx-http-3-rce-via-cve-2024-24989-mitigation-guide</guid><description>Proof of Concept code released for critical NGINX CVE-2024-24989 and CVE-2024-24990. Learn how to detect and patch these HTTP/3 vulnerabilities immediately.</description><pubDate>Sat, 16 May 2026 12:28:12 GMT</pubDate><category>CVE-2024-24989</category><category>CVE-2024-24990</category><category>NGINX</category><category>HTTP 3</category><category>RCE</category></item><item><title>CVE-2021-23017: NGINX DNS Resolver Buffer Overflow — Patch Now</title><link>https://runtimerebel.com/blog/cve-2021-23017-nginx-dns-resolver-buffer-overflow-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-23017-nginx-dns-resolver-buffer-overflow-patch-now</guid><description>An 18-year-old stack-based buffer overflow in the NGINX DNS resolver could lead to DoS or RCE. Learn how to secure your web server configuration today.</description><pubDate>Thu, 14 May 2026 16:46:42 GMT</pubDate><category>NGINX</category><category>CVE-2021-23017</category><category>DNS Resolver</category><category>Buffer Overflow</category><category>RCE</category></item><item><title>CVE-2026-42945: NGINX Rewrite Module Heap Overflow Enables RCE</title><link>https://runtimerebel.com/blog/cve-2026-42945-nginx-rewrite-module-heap-overflow-enables-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42945-nginx-rewrite-module-heap-overflow-enables-rce</guid><description>A critical 18-year-old heap buffer overflow in the NGINX rewrite module allows unauthenticated RCE. Learn how to detect and patch CVE-2026-42945.</description><pubDate>Thu, 14 May 2026 09:03:32 GMT</pubDate><category>CVE-2026-42945</category><category>NGINX</category><category>RCE</category><category>Heap Overflow</category><category>Ngx Http Rewrite Module</category></item><item><title>NGINX-UI Critical Flaw: Attackers Can Alter NGINX Configs</title><link>https://runtimerebel.com/blog/nginx-ui-critical-flaw-attackers-can-alter-nginx-configs</link><guid isPermaLink="true">https://runtimerebel.com/blog/nginx-ui-critical-flaw-attackers-can-alter-nginx-configs</guid><description>A critical flaw in nginx-ui allows attackers to remotely restart, create, modify, and delete NGINX configuration files, posing significant risk to web servers.</description><pubDate>Thu, 16 Apr 2026 00:47:36 GMT</pubDate><category>Nginx UI</category><category>NGINX</category><category>Configuration Manipulation</category><category>Critical Vulnerability</category><category>Web Server</category></item></channel></rss>