¡¾·ì϶¹«¸æ¡¿NGINX ngx_http_rewrite_module ¶Ñ»º³åÇøÒç¶Âí½Å(CVE-2026-9256)
°ä²¼¹¦·ò 2026-05-26Ò»¡¢·ì϶¸ÅÊö

NGINXÊÇÒ»¿î¸ß»úÄÜ¿ªÔ´Web·þÎñÆ÷¡¢·´Ïò´úÀí¼°¸ºÔØÆ½ºâÈí¼þ£¬£¬£¬£¬£¬¿í·ºÀûÓÃÓÚ»¥ÁªÍøÍøÕ¾¡¢APIÍø¹Ø¡¢ÔÆÔÉúƽ̨¼°±ßÔµ·þÎñ³¡¾°¡£¡£¡£¡£¡£¡£¡£¡£NGINXÖ§³ÖHTTP/HTTPS´úÀí¡¢»º´æ¡¢Rewrite¹æ¶¨¡¢Á÷Á¿µ÷¶È¼°°²È«½ÚÔìµÈÖ°ÄÜ£¬£¬£¬£¬£¬¾ß±¸¸ß²¢·¢¡¢µÍ×ÊÔ´¿÷Ë𼰽ýÝÅäÖõÈÌØµã£¬£¬£¬£¬£¬Í¬Ê±ÌṩóÒ×°æ±¾NGINX PlusÓÃÓÚÆóÒµ¼¶ÀûÓò¿Ê𡣡£¡£¡£¡£¡£¡£¡£
2026Äê5ÔÂ26ÈÕ£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½NGINX RewriteÄ£¿£¿£¿£¿£¿£¿£¿é¶Ñ»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚrewriteÖ¸ÁîÔÚ´¦ÖÃÔ̺¬³ÁµþPCRE²¶»ñ×éµÄÕýÔò±í°×ʽʱ£¬£¬£¬£¬£¬¶Ô¶à¸ö䶨Ãû²¶»ñÒýÓõÄÄÚ´æ´¦ÖôæÔÚȱµã£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâHTTPÒªÇó´¥·¢NGINX Worker¹ý³Ì²úÉúHeap-based Buffer Overflow£¬£¬£¬£¬£¬µ¼Ö·þÎñÒì³£³ÁÆô»ò»Ø¾ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ½ûÓÃASLR»ò¹¥»÷Õß¿ÉÄÜÈÆ¹ýASLR±£»£»£»£»£»¤µÄÇé¿öÏ£¬£¬£¬£¬£¬»¹¿ÉÄܽøÒ»²½ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÎÞÐèÉí·ÝÈÏÖ¤¼´¿ÉÀûÓ㬣¬£¬£¬£¬¿ÉÄܵ¼ÖÂÒµÎñÖжϡ¢·þÎñÆ÷ʧÏݼ°Ãô¸ÐÒµÎñÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
NGINX Plus 37.0.0
R32 <= NGINX Plus <= R36
NGINX Open Source 1.31.0
1.0.0 <= NGINX Open Source <= 1.30.1
0.1.17 <= NGINX Open Source <= 0.9.7
2.17.0 <= NGINX Instance Manager <= 2.22.0
5.9.0 <= F5 WAF for NGINX <= 5.13.0
5.2.0 <= NGINX App Protect WAF <= 5.8.0
4.10.0 <= NGINX App Protect WAF <= 4.16.0
F5 DoS for NGINX 4.9.0
4.3.0 <= NGINX App Protect DoS <= 4.7.0
2.0.0 <= NGINX Gateway Fabric <= 2.6.1
1.3.0 <= NGINX Gateway Fabric <= 1.6.2
5.0.0 <= NGINX Ingress Controller <= 5.4.2
4.0.0 <= NGINX Ingress Controller <= 4.0.1
3.5.0 <= NGINX Ingress Controller <= 3.7.2
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ÒÔ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
NGINX Plus 37.x >= 37.0.1
NGINX Plus R36 >= R36 P5
NGINX Plus R32 >= R32 P7
NGINX Open Source >= 1.31.1
NGINX Open Source >= 1.30.2
¶ÔÓÚ0.x¾É°æ±¾·ÖÖ§£º
0.1.17 <= NGINX Open Source <= 0.9.7
¹Ù·½ÒÑÉêÃ÷ Will not fix£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁÊÜÖ§³ÖµÄа汾·ÖÖ§¡£¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚNGINX Instance Manager¡¢F5 WAF for NGINX¡¢NGINX App Protect WAF¡¢F5 DoS for NGINX¡¢NGINX App Protect DoS¡¢NGINX Gateway Fabric¼°NGINX Ingress ControllerµÈ²úÆ·ÒÀÀµµ×²ãNGINX×é¼þ£¬£¬£¬£¬£¬½¨Òéͬ²½Éý¼¶Æäµ×²ãNGINX Open Source»òNGINX PlusÖÁÒѽ¨¸´°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://my.f5.com/manage/s/article/K000161377/
3.2 һʱ´ëÊ©
ÔÚÎÞ·¨Á¢¼´Éý¼¶ÖÁ¹Ù·½½¨¸´°æ±¾µÄÇé¿öÏ£¬£¬£¬£¬£¬½¨ÒéÓû§ÓÅÏÈÅŲ鲢µ÷ÕûNGINXÅäÖÃÖеÄrewrite¹æ¶¨£¬£¬£¬£¬£¬Ô¤·ÀʹÓÃ$1¡¢$2µÈ䶨ÃûPCRE²¶»ñ±äÁ¿£¬£¬£¬£¬£¬¸ÄÓö¨Ãû²¶»ñ×é½øÐвÎÊýÒýÓ㻣»£»£»£»Í¬Ê±²»ÈÝÔÚrewrite¹æ¶¨ÖÐʹÓóÁµþ¡¢Ç¶Ì×»ò¹ýÓÚ¸´ÔÓµÄÕýÔò²¶»ñÂß¼£¬£¬£¬£¬£¬Ï÷¼õÓÉ±í²¿¿É¿ØURI»òQuery String´¥·¢Òì³£ÄÚ´æ´¦ÖõķçÏÕ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿É²Î¿¼ÈçÏ·½Ê½Åú¸ÄÅäÖ㺽«rewrite ^/users/([0-9]+)/profile/(.*)$ /profile.php?id=$1&tab=$2 lastµ÷ÕûΪrewrite ^/users/(?[0-9]+)/profile/(?
.*)$ /profile.php?id=$user_id&tab=$section last¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬½¨ÒéÔÚWAF»ò·´Ïò´úÀí²ãÏÞ¶ÈÒì³£³¤URI¡¢Òì³£Query String¼°ÒÉËÆ¶ñÒâÒªÇ󣬣¬£¬£¬£¬ÆôÓÃASLR¡¢DEPµÈϵͳÄÚ´æ±£»£»£»£»£»¤»úÔ죬£¬£¬£¬£¬²¢¶ÔNGINX WorkerÒì³£Í˳ö¡¢Crash¼°ÆµÈÔ³ÁÆôÐÐΪÅäÖÃ¼à¿ØËß¾¯£¬£¬£¬£¬£¬¶¨ÆÚÉó¼ÆNGINXÅäÖÃÎļþ£¬£¬£¬£¬£¬³ÖÐøÅŲé¸ß·çÏÕrewrite¹æ¶¨¡£¡£¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://my.f5.com/manage/s/article/K000161377/
https://nvd.nist.gov/vuln/detail/CVE-2026-9256


¾©¹«Íø°²±¸11010802024551ºÅ