
Zhenpeng (Leo) Lin
@Markak_ • 3,549 subscribers
AI x Security @depthfirstlabs, Ph.D., CTF player @Nu1L_team, now @StrawHat_CTF. #Pwn2Own winner. Author of #DirtyCred #Badiouring
Shorts
Videos

Open-sourcing our RCE implementation for CVE-2026-42533! This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!). F5 released the security advisory a week ago on July 15th. Fun fact: this bug appears to have been found concurrently by multiple groups. Our team at depthfirst caught it using our internal systems, right alongside CVE-2026-42530, a separate issue in NGINX’s HTTP/3 QPACK implementation.
Zhenpeng (Leo) Lin29,695 Aufrufe • vor 7 Tagen

NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in NGINX impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at
Zhenpeng (Leo) Lin209,069 Aufrufe • vor 2 Monaten
Keine weiteren Inhalte verfügbar