CVE-2026-42533: NGINX ASLR-enabled network RCE
CVE-2026-42533 is verified against nginx/nginx · github affected versions: NGINX security index lists Open Source 0.9.6-1.31.2 as vulnerable and 1.31.3+ or 1.30.4+ as not vulnerable. F5 also lists NGINX Plus 37.0.0.1-37.0.2.1 fixed in 37.0.3.1 and R33-R36 fixed in R36 P7. vulnerability class: RCE This critical reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00308.
pruva-verify REPRO-2026-00308 curl -O https://pruva.dev/api/v1/reproductions/REPRO-2026-00308/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh Demonstrate genuine remote command execution for CVE-2026-42533 against NGINX commit 28219209e0b4f9e155fd8bd91ab81b8ac30628f2 while ASLR remains enabled. The attacker must be a separate network peer and may only use the target's real HTTP/TCP listeners. The proof must create a target-local command marker that is subsequently observable through the application boundary.
The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.
Loading session...
Scripts, logs, diffs, and output captured during the reproduction.