buffer overflow149 Two Bytes to RCE: Chaining Rift + PoolSlip into an ASLR-Independent nginx 1.30.0 Exploit
A two-bug nginx 1.30.0 chain: CVE-2026-42945 (Rift) heap overflow + CVE-2026-9256 (PoolSlip) heap over-read combine into an ASLR-independent remote system() call at…










