Tengine 3.1.0 affected by upstream nginx CVE-2026-42945 & CVE-2026-9256 — heads-up on upcoming Orca blog
Hi Tengine maintainers,
I'm part of Orca Security's Threat Research Team. While researching CVE-2026-42945 ("NGINX Rift") and CVE-2026-9256 ("nginx-poolslip"), we confirmed that Tengine 3.1.0 - based on nginx 1.24.0 - inherits both bugs in ngx_http_script.c. We reproduced them from source with working PoCs and ASAN-confirmed crashes.
We also saw the commits on master addressing both issues and the discussion (#2036) planning the 3.2.0 release targeted for June 30 - thanks for moving on these.
We're planning to publish a research blog on June 16. To be clear on scope: we are not claiming any new CVE IDs - these are the existing upstream nginx CVEs. Our contribution is confirming Tengine as affected with reproducible proof and quantifying internet-facing exposure. The post will point readers to the fixes on master, the upcoming 3.2.0 release, and interim mitigations, and won't include a runnable PoC.
We've verified our findings directly against the 3.1.0 source, so this is a heads-up rather than a request for review, but if there's anything you'd like us to add, or a statement you'd like included, we're glad to.
So we can keep our publish date, it would help to hear back by June 14.
Thanks for your work on Tengine,
Orca Security Threat Research Team
Source: alibaba/tengine