Two bytes to RCE: chaining rift + PoolSlip into an ASLR-independent nginx 1.30.0 exploit
Author: y198 (published on the Verichains blog) Published: June 6, 2026 Source: https://blog.verichains.io/p/two-bytes-to-rce-chaining-rift-poolslip Summary This Verichains writeup chains two separately disclosed nginx rewrite-engine memory-corruption bugs — CVE-2026-42945 (“rift”), a heap-overflow write primitive, and CVE-2026-9256 (“PoolSlip”), a heap over-read leak primitive — into a single remote code execution exploit against nginx 1.30.0 that works with ASLR … Read more