Loading video...
Video Failed to Load
‼️🚨 MAJOR IMPACT: AI just found an 18-year-old NGINX critical remote code execution vulnerability. It has been disclosed on GitHub including PoC code. - Affects NGINX 0.6.27 through 1.30.0 - Triggered via the rewrite and set directives in config - Update NGINX ASAP - NGINX is a widely used... show more
953,684 views • 4 months ago •via X (Twitter)
39 Comments

...

Tough times for NGinx fans 🤣

Source: Write up by @Markak_:

Missing an important part which is that it affects installations that have ASLR disabled. The PoC specifically disables it.

NGINX users should update regardless, as the vulnerability can still enable DoS.

Absolutely!

Just needs ASLR disabled, lelz

Still DoS without ASLR, lolzzz

Mehh, pretty boring if you ask me. Inflation of standards on vulnerabilities is getting higher and higher for me

Fight ai with ai 😈

This is exactly what Jensen predicted.

Jenson just wants GPU in circulation 😭

@akaclandestine Man, this is depressing

@akaclandestine Yes. Shutdown the internet now!

@akaclandestine Just updated all my servers lol. Can't sleep in peace without a new exploit in the wild

An 18-year-old RCE in NGINX found by AI. One of the most audited codebases on the planet, and a model spotted what humans missed for nearly two decades. The real shift: every C codebase is now potentially 0-day territory. Time-to-discover just collapsed.

18 years undisclosed just means 18 years someone else was sitting on it quietly.

This is too much now!

the requirements to trigger this are too much rewrite+set+question mark in rewrite rule+attacker knows the rewrite rules

@grok what’s the CVSS Score and Attack Complexity? And requirement

PoC code already on GitHub means the window between disclosure and active exploitation is not weeks anymore. It is hours. If your infrastructure team has not seen this yet, forward it before you finish reading this tweet. NGINX 0.6.27 through 1.30.0 is a wide net.

18 years in production and nobody caught it. thats the scary part if you run nginx, check your version right now - anything below 1.30.0 is exposed

skill issue don't use default #nginx or #apache2 both trash use golang based webservers only 🙌👌

Just run the command below to verify if ASLR is enabled or not cat /proc/sys/kernel/randomize_va_space If the result shows 0 it means that it is disabled so you should enable it. How to enable it? 1. Open the sysctl.conf file: sudo nano /etc/sysctl.conf 2. Add the line below: kernel.randomize_va_space = 2 Then apply it with the command below sudo sysctl -p

are we adding ai to everything? like how are you sure it was ai?

I don’t know why but I always stayed away from NGINX because my gut told me to… no particular reason. Now I will trust my gut more often

Та йоб вашу мать хватіт уже я заєбался

Was that a Mythos find ?

Is this also a thing when you use nginx as a load balancer?

internet said f*ck your vacation good sir..

new day new vibe

换个角度想:18年的NGINX RCE漏洞意味着在AI发现之前很可能已经有nation-state actors在悄悄exploit了。AI fuzzing不是创造风险而是expose已经存在的风险。更关键的implication:所有超过10年的C/C++ infra project里可能都藏着类似级别的0-day。Linux kernel, OpenSSL, PostgreSQL——AI code audit的demand会在未来12个月爆发

@grok, should I be concerned if I don’t run infra?

Thanks for sharing this. The interaction between rewrite and set directives is concerning. Are there known workarounds for systems that can't upgrade NGINX immediately, or is updating the only safe path?

meanwhile devops, sec, sre teams

The fact that AI found this before any human security researcher formally disclosed it is the part of this story that deserves more attention than the vulnerability itself. The tools have changed. The threat surface has not.

This is a reminder to never leave server config untouched just because it works. 18 years is a long time for a vulnerability to sit undetected in something this widely used

18 years. That code probably predates half the devs who'll patch it today.

That's why Caddy is the goat, THE GOAT
