<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/vulnerability/</link><description>Recent content in Vulnerability on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 21 Jul 2026 13:12:48 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/vulnerability/index.xml" rel="self" type="application/rss+xml"/><item><title>Nginx Map Regex Flaw Lets One Request Take Over a Server</title><link>https://hackingpassion.com/nginx-map-regex-rce/</link><pubDate>Tue, 21 Jul 2026 13:12:48 +0200</pubDate><guid>https://hackingpassion.com/nginx-map-regex-rce/</guid><description>&lt;p>For 15 years, a single crafted web request could quietly take over an nginx server, the software that receives and routes incoming traffic for roughly a third of the websites people load.
The flaw was documented in public years ago and marked as something to fix, and the danger went unrecognised until a researcher looked again last week.&lt;/p>
&lt;p>nginx is the piece of software sitting in front of a large slice of the internet. When you open a site, there is a good chance nginx is the first thing that reads your request, deals with the encryption, decides where the request should go, and passes it to whatever runs the site behind it.&lt;/p></description></item><item><title>7-Zip Carried a Hidden Code Execution Flaw in Its XZ Files for Eight Years</title><link>https://hackingpassion.com/7-zip-xz-heap-overflow/</link><pubDate>Mon, 20 Jul 2026 15:55:24 +0200</pubDate><guid>https://hackingpassion.com/7-zip-xz-heap-overflow/</guid><description>&lt;p>You opened an archive in 7-Zip, and the code that let it take over your machine had been sitting there since 2018. It was quietly patched on June 25. You were not told what it fixed until three weeks later.&lt;/p>
&lt;p>On July 15, the Zero Day Initiative laid out the details in advisory &lt;strong>ZDI-26-444&lt;/strong>, tracked as &lt;strong>CVE-2026-14266&lt;/strong>. It described a flaw in 7-Zip that lets a malicious archive run code the moment you open it. Before that day, the only thing 7-Zip had said about it was a June release that explained nothing.&lt;/p></description></item><item><title>Ghost CMS SQL Injection Stole Admin Keys From 700 Websites With One Request</title><link>https://hackingpassion.com/ghost-cms-cve-2026-26980/</link><pubDate>Tue, 26 May 2026 12:51:20 +0200</pubDate><guid>https://hackingpassion.com/ghost-cms-cve-2026-26980/</guid><description>&lt;p>A &lt;strong>SQL injection vulnerability&lt;/strong> in &lt;strong>Ghost CMS&lt;/strong> has turned Harvard University, Oxford University, and DuckDuckGo into malware distribution platforms. Visitors arrive at a page they trust completely, a fake Cloudflare verification prompt appears, and their machine gets infected if they follow the instructions. More than &lt;strong>700 sites&lt;/strong>. Software that had never had an unauthenticated critical vulnerability in its entire history.&lt;/p>
&lt;p>&lt;strong>Ghost CMS&lt;/strong> is publishing software built on Node.js, used for newsletters, membership sites, and independent blogs. It is open source and free to self-host, with a paid hosted version called Ghost Pro. More than &lt;strong>100,000 active installations&lt;/strong> and more than &lt;strong>50,000 GitHub stars&lt;/strong>.&lt;/p></description></item><item><title>NGINX Has Had This Bug Since 2008 and One Request Is Enough to Trigger It</title><link>https://hackingpassion.com/nginx-rift-cve-2026-42945/</link><pubDate>Thu, 14 May 2026 13:22:10 +0200</pubDate><guid>https://hackingpassion.com/nginx-rift-cve-2026-42945/</guid><description>&lt;p>&lt;strong>NGINX Rift:&lt;/strong> An 18-year-old memory corruption bug in NGINX, the web server running on roughly one-third of all websites globally, lets an unauthenticated attacker crash a server with a single crafted HTTP request. On systems where ASLR is disabled, that same request achieves remote code execution. The bug has been in every standard build since 2008. It was publicly disclosed yesterday, after being found by an AI system in six hours.&lt;/p></description></item><item><title>Nginx-UI MCPwn (CVE-2026-33032): Full Server Takeover With One Unauthenticated Request</title><link>https://hackingpassion.com/nginx-ui-mcpwn-cve-2026-33032/</link><pubDate>Thu, 16 Apr 2026 11:11:43 +0200</pubDate><guid>https://hackingpassion.com/nginx-ui-mcpwn-cve-2026-33032/</guid><description>&lt;p>A critical vulnerability in nginx-ui has been actively exploited since March 2026, and it gives any attacker on the network full control over the nginx server behind it without a single credential. &lt;strong>CVE-2026-33032&lt;/strong> scores &lt;strong>9.8 on the CVSS scale&lt;/strong>, sits inside an AI integration that was added to the tool in late 2025, and the entire root cause turned out to be 27 characters of missing code. Recorded Future assigned it a risk score of &lt;strong>94 out of 100&lt;/strong>. The researchers who found it named it &lt;strong>MCPwn&lt;/strong>. 😏&lt;/p></description></item><item><title>Docker Had a 10-Year Security Bypass Hidden in Plain Sight</title><link>https://hackingpassion.com/docker-authorization-bypass-cve-2026-34040/</link><pubDate>Sun, 12 Apr 2026 14:10:45 +0200</pubDate><guid>https://hackingpassion.com/docker-authorization-bypass-cve-2026-34040/</guid><description>&lt;p>&lt;strong>Docker&amp;rsquo;s Security Layer Has Been Broken Since 2016, And The Fix Doesn&amp;rsquo;t Finish the Job.&lt;/strong>
One padded HTTP request. That is all it takes to silently disable every authorization plugin in Docker, open a direct path to the host filesystem, and walk out with AWS credentials, SSH keys, and Kubernetes cluster access. The authorization logs show nothing unusual. 😏&lt;/p>
&lt;p>When a request hits the Docker API, an authorization plugin steps in before anything else happens. That plugin checks exactly what is being requested before the Docker daemon gets to act on it, and enterprises run tools like Open Policy Agent, Prisma Cloud, or Casbin for this job, configured with rules about what containers are and are not allowed to do.&lt;/p></description></item><item><title>Two Missing Characters Nearly Compromised the AWS Supply Chain</title><link>https://hackingpassion.com/aws-supply-chain-vulnerability/</link><pubDate>Sat, 17 Jan 2026 13:49:16 +0100</pubDate><guid>https://hackingpassion.com/aws-supply-chain-vulnerability/</guid><description>&lt;p>Netflix. Twitch. iCloud. The servers of the CIA and NSA. 30% of all cloud infrastructure worldwide runs on Amazon Web Services. Two missing characters in a regex filter nearly compromised all of it. 😬&lt;/p>
&lt;p>A &lt;code>^&lt;/code> at the start and a &lt;code>$&lt;/code> at the end. That&amp;rsquo;s what was missing from a security filter, and that&amp;rsquo;s all it would have taken for attackers to inject malicious code into the AWS JavaScript SDK.&lt;/p></description></item></channel></rss>