<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #heap-overflow</title><description>Articles tagged heap-overflow on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>F5 patched an 18-year-old NGINX bug. Attackers can RCE a third of the web with one crafted request.</title><link>https://devtake.dev/article/nginx-rift-18-year-rce/</link><guid isPermaLink="true">https://devtake.dev/article/nginx-rift-18-year-rce/</guid><description>F5 disclosed CVE-2026-42945 on May 13 after depthfirst&apos;s analyzer found a heap overflow in a 2008 commit. NGINX 1.31.0 ships the patch, every Plus tier needs an upgrade.</description><pubDate>Thu, 14 May 2026 10:30:00 GMT</pubDate><category>security</category><category>security</category><category>nginx</category><category>f5</category><category>cve-2026-42945</category><category>rce</category><category>heap-overflow</category><category>depthfirst</category><category>ai-security</category><author>luca-reinhardt</author></item></channel></rss>