XMPP Service Operators - 2026-05-14


  1. moparisthebest

    unauthenticated RCE in nginx, upgrade immediately https://depthfirst.com/nginx-rift

    😭 1
  2. icebound.dev

    > unauthenticated RCE in nginx, upgrade immediately https://depthfirst.com/nginx-rift was this also found by anthropics new toy?

  3. icebound.dev

    Debian doesn't appear to have pushed a DSA for this yet...

  4. icebound.dev

    https://app.opencve.io/cve/CVE-2026-42945 checking the CVE info, anything below 1.31.0 is vulnerable, Arch Linux updated the package, but Debian is still sitting at 1.26.3

  5. Sunglocto (sunglocto.net)

    icebound.dev: https://archlinux.org/packages/extra/x86_64/nginx/ shows nginx at 1.30.1-1

  6. Sunglocto (sunglocto.net)

    hmm actually that package seems to have been updated yesterday

  7. icebound.dev

    Sunglocto (sunglocto.net), oh I must have misread the version... okay then Arch is vulnerable too :p

  8. icebound.dev

    all the right numbers are in the string, just not in the right order >:)

  9. icebound.dev

    good thing OpenBSD httpd isn't affected, like usual :p

  10. moparisthebest

    nope arch is all good (I upgraded before I posted) that's the fixed version

  11. icebound.dev

    moparisthebest, yeah sorry I missed the constaint < 1.30.1

  12. icebound.dev

    1.31.0 is also good

  13. icebound.dev

    iirc 1.31.0 is nginx-mainline and 1.30.1 is nginx

  14. icebound.dev

    hence the confusion, apologies

  15. AZERTY keyboard [admin@copper9.host.planetofnix.com]

    > good thing OpenBSD httpd isn't affected, like usual :p hell ye