<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/how-orca-traced-an-nginx-flaw-to-1-45-million-tengine-servers-all-running-vulnerable-code-flnilqhmr" -->

---
title: How Orca Traced an nginx Flaw to 1.45 Million Tengine...
description: Orca&#x27;s Threat Research Team discovered that Tengine, Alibaba&#x27;s nginx fork deployed on 1.45 million internet-facing servers, carries the same vulnerable code as...
canonical: https://daily.dev/posts/how-orca-traced-an-nginx-flaw-to-1-45-million-tengine-servers-all-running-vulnerable-code-flnilqhmr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code | daily.dev
og:description: Orca&#x27;s Threat Research Team discovered that Tengine, Alibaba&#x27;s nginx fork deployed on 1.45 million internet-facing servers, carries the same vulnerable code as...
og:url: https://daily.dev/posts/how-orca-traced-an-nginx-flaw-to-1-45-million-tengine-servers-all-running-vulnerable-code-flnilqhmr
og:image: https://api.daily.dev/og/posts/FLNiLQHmR.png
og:image:alt: How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code

**[Orca Security Blog](https://daily.dev/sources/orca-security-blog)** · 10 min read · 1 upvotes · 0 comments

## Summary

Orca's Threat Research Team discovered that Tengine, Alibaba's nginx fork deployed on 1.45 million internet-facing servers, carries the same vulnerable code as two critical nginx CVEs (CVE-2026-42945 and CVE-2026-9256) — both heap buffer overflows in ngx_http_script.c with CVSS 9.2. While the industry patched nginx and moved on, Tengine remained unpatched for nearly two decades. Orca compiled Tengine 3.1.0 from source, built working exploits for both CVEs, and confirmed crashes via ASAN stack traces. A single unauthenticated HTTP request can crash a Tengine worker process, enabling sustained denial of service and potentially code execution. As of June 10, 2026, fixes landed in Tengine's main branch, with a 3.2.0 release targeting June 30, 2026. Until then, every released Tengine version remains vulnerable. Mitigation options include building from the latest master branch commit or switching to upstream nginx.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://orca.security/resources/blog/tengine-servers-nginx-vulnerability>

## Similar posts on daily.dev

- [AI agent finds 18-year-old remote code execution flaw in Nginx](https://daily.dev/posts/ai-agent-finds-18-year-old-remote-code-execution-flaw-in-nginx-ogqskl35h) · CSO Online · 11 upvotes · 2 comments

---

Tags: [#security](https://daily.dev/tags/security), [#nginx](https://daily.dev/tags/nginx)

[View this post on daily.dev](https://daily.dev/posts/how-orca-traced-an-nginx-flaw-to-1-45-million-tengine-servers-all-running-vulnerable-code-flnilqhmr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code","url":"https://daily.dev/posts/how-orca-traced-an-nginx-flaw-to-1-45-million-tengine-servers-all-running-vulnerable-code-flnilqhmr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/how-orca-traced-an-nginx-flaw-to-1-45-million-tengine-servers-all-running-vulnerable-code-flnilqhmr"},"datePublished":"2026-06-16T12:52:58.892Z","dateModified":"2026-06-17T10:20:38.269Z","description":"Orca's Threat Research Team discovered that Tengine, Alibaba's nginx fork deployed on 1.45 million internet-facing servers, carries the same vulnerable code as...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7d309bf6d689e9b4a1ac854086aeb1c7?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7d309bf6d689e9b4a1ac854086aeb1c7?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Orca Security Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Orca Security Blog","logo":"https://media.daily.dev/image/upload/s--kkQFNboJ--/f_auto,q_auto/v1780213281/logos/orca-security-blog?_a=BAMAMiWQ0","url":"https://daily.dev/sources/orca-security-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/how-orca-traced-an-nginx-flaw-to-1-45-million-tengine-servers-all-running-vulnerable-code-flnilqhmr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,nginx","timeRequired":"PT10M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Orca Security Blog","item":"https://daily.dev/sources/orca-security-blog"},{"@type":"ListItem","position":3,"name":"How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code"}]}
```

