Description
Allowing null byte character (ASCII 0x00) in the URL can lead to a severe security risk. If the user can manipulate file contents on the server, this vulnerability may result in arbitrary PHP code execution, enabling attackers to take control of the server and execute unauthorized commands.
Recommendation
Upgrade Nginx to a version that properly sanitizes input and disallows null byte characters in URLs.
References
Could your website be exposed too?
SmartScanner can check your website for Nginx Null Byte Code Execution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Nginx Code Execution due to Misconfiguration - Vulnerability
- Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal - CVE-2024-47169
- LiquidJS is Vulnerable to Remote Code Execution - CVE-2026-45618
- angular-base64-upload vulnerable to unauthenticated remote code execution - CVE-2024-42640


