New NGINX 0-Day RCE “nginx-poolslip” Threatens Millions of Servers
ID: 7e578a5b-c6ae-5880-8cc0-501c83fd8ab6
STIX ID: report--7e578a5b-c6ae-5880-8cc0-501c83fd8ab6
Feed Name: GBHackers
Threat Score
A newly disclosed zero-day dubbed **nginx-poolslip** affects NGINX 1.31.0, enabling unauthenticated remote code execution and bypassing ASLR; it potentially exposes millions of servers, has no patch or CVE yet, and NebSec is coordinating responsible disclosure while urging administrators to apply mitigations (WAF rules, ASLR checks, interface restrictions) until an official fix is released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
