CVE-2017-7529 is an integer overflow vulnerability in the Nginx range filter module affecting Nginx versions from 0.5.6 through 1.13.2. A specially crafted HTTP Range request containing malicious byte ranges can trigger the overflow and cause the server to return potentially sensitive information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept and exploitation toolkit for CVE-2017-7529, a remote integer overflow vulnerability in older versions of Nginx (1.1x, except 1.12). The repository contains two main Python scripts: - 'vulnchecker.py': A script to check if a given Nginx server is vulnerable by sending crafted HTTP Range headers and analyzing the response codes and headers. - 'exploit.py': A script that exploits the vulnerability by sending a malicious Range header to the target server, attempting to read sensitive HTTP headers and potentially reveal internal information such as real IP addresses. Both scripts require the 'requests' library and are run from the command line with the target URL as an argument. The exploit works by leveraging the integer overflow in the HTTP Range header processing of vulnerable Nginx servers, causing the server to return unintended data. The repository is operational and provides working code for both detection and exploitation, targeting network-accessible Nginx servers.
This repository contains a proof-of-concept (PoC) exploit targeting Nginx 1.13.2, specifically exploiting a vulnerability in the handling of HTTP Range headers. The main exploit logic is implemented in 'poc.py', a Python script that sends a specially crafted HTTP request with a manipulated Range header to a user-supplied URL (typically http://your-ip:8080/). The script calculates the content length of the response and constructs a Range header designed to trigger the vulnerability, potentially exposing sensitive data from the server. The repository also includes a Dockerfile (which appears to be a duplicate of poc.py, likely by mistake), an Nginx configuration file (conf.d/default.conf) that sets up a reverse proxy and caching, and a docker-compose.yml file that deploys Nginx 1.13.2 with the provided configuration. The exploit is network-based and requires the target to be accessible over HTTP on port 8080. The endpoints and file paths in the configuration are fingerprintable and may be useful for detection or further exploitation. The exploit is a PoC and does not provide a weaponized or customizable payload.
This repository provides a proof-of-concept exploit for CVE-2017-7529, an integer overflow vulnerability in Nginx (versions 1.13.2 and below) that allows attackers to leak memory content via a crafted HTTP Range header. The repository contains three files: a README.md with background and usage instructions, a docker-compose.yml for setting up a vulnerable Nginx environment (using the official nginx:1.12 Docker image), and poc.py, a Python script that automates the exploitation process. The exploit works by sending a GET request with a malicious Range header to the target server; if the server is vulnerable, it responds with a 206 Partial Content response containing leaked memory data. The script can check for vulnerability and attempt exploitation, printing the first 256 bytes of leaked data. The attack vector is network-based, targeting HTTP endpoints. The repository is operational and suitable for demonstrating the vulnerability and its impact.
This repository contains a single Python proof-of-concept exploit (POC_CVE-2017-7529.py) and a brief README. The exploit targets Nginx version 1.13.2, specifically CVE-2017-7529, a remote integer overflow vulnerability triggered via a crafted HTTP Range header. The script takes a target URL as input, sends a specially crafted Range header in an HTTP GET request, and analyzes the response to determine if the server is vulnerable. If successful, it prints the response headers and body, and logs that the server is vulnerable. The exploit is network-based and requires the target to be accessible over HTTP(S) and to process Range headers. The repository is structured simply, with the main exploit logic in a single Python file and no additional payloads or modules.
This repository contains a proof-of-concept exploit for CVE-2017-7529, an integer overflow vulnerability in the Nginx range filter module affecting versions 0.5.6 up to and including 1.13.2. The repository consists of a README file with usage instructions and a single Python script ('cve-2017-7529.py') that implements the exploit. The script takes a target URL as input, sends a specially crafted HTTP request with a malicious 'Range' header, and attempts to trigger the vulnerability to leak sensitive information from the server's memory. If successful, the script prints the HTTP response, including any leaked data. The exploit targets network-accessible Nginx servers and demonstrates the vulnerability but does not provide a weaponized or automated payload beyond proof-of-concept data leakage.
This repository provides a proof-of-concept (POC) exploit for CVE-2017-7529, a vulnerability in Nginx (tested on version 1.13.2) that allows out-of-bounds reading from the cache when processing malicious Range headers. The repository includes a Docker-based environment to deploy a vulnerable Nginx instance with a specific configuration (reverse proxy with caching enabled). The main exploit is implemented in 'poc.py', a Python script that sends a specially crafted HTTP request with a malicious Range header to the Nginx server running on port 8080. If successful, the exploit retrieves data from the Nginx cache that may include sensitive HTTP headers and file metadata. The README provides background on the vulnerability, setup instructions, and usage examples. The repository structure is clear: 'Dockerfile', 'docker-compose.yml', and 'default.conf' set up the vulnerable environment, while 'poc.py' is the exploit script. No fake or detection-only scripts are present.
This repository contains a Python exploit script (CVE-2017-7529.py) targeting the integer overflow vulnerability (CVE-2017-7529) in the Nginx range filter module, affecting versions 0.5.6 through 1.13.2. The exploit works by sending a specially crafted HTTP Range header to a target Nginx server, which can trigger an integer overflow and cause the server to leak potentially sensitive information from memory. The script can check if a target is vulnerable and, if so, attempts to extract and display leaked data in a hexdump format. The repository also includes a README.md with usage instructions and a sample target URL. The exploit is operational and requires the attacker to specify the target URL; it does not require authentication or special privileges. The main attack vector is network-based, exploiting accessible HTTP/S endpoints on vulnerable Nginx servers.
This repository contains a Python proof-of-concept exploit for CVE-2017-7529, an integer overflow vulnerability in the Nginx range filter module (versions 0.5.6 up to and including 1.13.2). The main file, CVE-2017-7529_PoC.py, allows a user to check if a target Nginx server is vulnerable and, if so, attempts to leak memory from the server by sending specially crafted HTTP Range requests. The script uses the requests library to interact with the target and provides colored terminal output for status messages. The exploit is run from the command line, taking a target URL as input and optionally performing only a vulnerability check. The README is minimal and provides only the name of the exploit. No hardcoded endpoints are present; the target is specified by the user at runtime. The exploit is a standalone proof-of-concept and does not include weaponized or post-exploitation features.
This repository contains a single Python script, 'cve-nginx-1.10.3.py', which is a proof-of-concept exploit for CVE-2017-7529, a remote integer overflow vulnerability in Nginx (version 1.10.3). The script takes a target URL as a command-line argument and sends a specially crafted HTTP Range header to the server. If the server responds with a 206 status code and includes a 'Content-Range' header, the script reports the target as vulnerable. The script uses the 'requests' library for HTTP communication and logs the results. There are no hardcoded endpoints; the user supplies the target URL. The repository is straightforward, containing only this exploit script, and is intended to test for the presence of the vulnerability rather than to weaponize it.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An integer-overflow vulnerability in nginx's range filter that can be triggered with a crafted HTTP Range header, potentially causing disclosure of sensitive process memory through a malformed multipart byte-range response.
An integer overflow vulnerability in Nginx's range filter handling that can be triggered via a crafted Range header, leading to unintended partial content responses and information disclosure.
An information disclosure vulnerability in Nginx involving an integer overflow in the range filter.
A specific known vulnerability affecting the outdated nginx 1.6.1 component included in the Lantronix EDS-MD firmware.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.