涵盖的 CVE:CVE-2026-28755、CVE-2026-42926、CVE-2026-9256、CVE-2026-42055、CVE-2026-42533
创建者:Pratik Chhetri
报告日期: 2026-07-28
| CVE | 组件 | 主要问题 | 修复的开源版本 | 优先级 |
|---|---|---|---|---|
| CVE-2026-28755 | ngx_stream_ssl_module | stream mTLS 中的 OCSP 结果绕过 | 1.29.7+, 1.28.3+ | P3 / P2 |
| CVE-2026-42926 | ngx_http_proxy_v2_module | HTTP/2 上游请求注入 | 1.31.0+, 1.30.1+ | P2 |
| CVE-2026-9256 | ngx_http_rewrite_module | 通过重叠的 PCRE 捕获导致的堆溢出 | 1.31.1+, 1.30.2+ | P1 |
| CVE-2026-42055 | ngx_http_proxy_v2_module, ngx_http_grpc_module | HTTP/2/gRPC 大请求头导致的堆溢出 | 1.31.2+, 1.30.3+ | P1 |
| CVE-2026-42533 | 使用正则匹配的 map 指令 | 通过正则 map 捕获覆盖导致的堆溢出 | 1.31.3+, 1.30.4+ | P0/P1 |
这五个漏洞是依赖配置的 NGINX 数据面风险。
以下场景风险最高:
rewrite 和 map 配置先打补丁,再审计配置暴露面。
flowchart TD
A[Remote requester] --> B[Internet-facing NGINX data plane]
B --> C{Vulnerable configuration present?}
C -->|stream mTLS + OCSP| D1[CVE-2026-28755]
C -->|proxy_http_version 2 + proxy_set_body| D2[CVE-2026-42926]
C -->|rewrite overlapping captures| D3[CVE-2026-9256]
C -->|gRPC / HTTP2 + large headers| D4[CVE-2026-42055]
C -->|regex map capture ordering| D5[CVE-2026-42533]
D1 --> E1[Revoked cert may be accepted]
D2 --> E2[Upstream HTTP/2 frame injection]
D3 --> E3[Worker crash or possible code execution]
D4 --> E3
D5 --> E3
| 项目 | 结果 |
|---|---|
| CISA KEV | 五个 CVE 均未发现 |
| 在野利用 | 所审查的公开来源中未发现 |
| 勒索软件使用情况 | 未发现 |
| APT 归属 | 未发现 |
| Exploit-DB | 未发现 |
| Metasploit | 未发现 |
| 公开 GitHub 活动 | 在 CVE-2026-42926、CVE-2026-9256、CVE-2026-42055、CVE-2026-42533 中发现 |
| 公开扫描器 | 在 CVE-2026-42533 中发现 |
| 最高 EPSS | CVE-2026-9256,为 0.098840 |
timeline
title NGINX 2026 CVE Timeline
2026-03-24 : CVE-2026-28755 fixed in nginx 1.28.3 / 1.29.7
2026-05-13 : CVE-2026-42926 fixed in nginx 1.30.1 / 1.31.0
2026-05-22 : CVE-2026-9256 fixed in nginx 1.30.2 / 1.31.1
2026-06-17 : CVE-2026-42055 fixed in nginx 1.30.3 / 1.31.2
2026-07-15 : CVE-2026-42533 fixed in nginx 1.30.4 / 1.31.3
2026-07-28 : CTI package finalized
在 NGINX 配置中搜索以下指令和模式:
ssl_verify_client on
ssl_ocsp on
proxy_http_version 2
proxy_set_body
grpc_pass
ignore_invalid_headers off
large_client_header_buffers
rewrite
map
regex captures: $1 $2 $3 ...
高风险组合:
| CVE | 高风险配置 |
|---|---|
| CVE-2026-28755 | 在 stream TLS 客户端认证部署中使用 ssl_verify_client on + ssl_ocsp on |
| CVE-2026-42926 | proxy_http_version 2 + proxy_set_body |
| CVE-2026-9256 | rewrite 正则使用不同的重叠 PCRE 捕获,且替换引用了多个捕获 |
| CVE-2026-42055 | grpc_pass 或 proxy_http_version 2 + ignore_invalid_headers off + large_client_header_buffers 超过 2 MB |
| CVE-2026-42533 | 正则 map 和字符串表达式以易受攻击的顺序引用正则捕获变量 |
nginx worker process exited
exited on signal
segfault
core dumped
CrashLoopBackOff
unexpected 5xx spike
nginx worker process -> sh / bash / curl / wget / nc / ncat / powershell
Large HTTP/2 headers
Unexpected gRPC upstream failures
Upstream request desynchronization
TLS client certificate accepted despite OCSP revoked status
| 环境 | 风险 | 优先级 | 行动 |
|---|---|---|---|
| 面向互联网且存在正则 map 暴露的 NGINX | 严重 | P0/P1 | 升级到 1.30.4 / 1.31.3 或已修复的 Plus 版本 |
| 面向互联网且存在 HTTP/2/gRPC 大请求头暴露的 NGINX | 高 | P1 | 打补丁并移除不安全的请求头配置 |
| 存在重叠捕获的 NGINX rewrite 规则 | 高 | P1 | 打补丁并重写易受攻击的正则模式 |
使用 proxy_set_body 的 HTTP/2 上游代理 | 中 | P2 | 打补丁或更改 HTTP 上游版本 |
| 带 OCSP 吊销检查的 stream mTLS | 中 | P2/P3 | 打补丁并验证已吊销证书的行为 |
| 不面向互联网且无易受攻击指令的 NGINX | 低-中 | P3 | 按正常周期打补丁并监控 |
| 指标类型 | 状态 |
|---|---|
| 攻击者 IP | 未发现 |
| 攻击者域名 | 未发现 |
| 恶意 URL | 未发现 |
| 恶意软件哈希 | 未发现 |
| 注册表项 | 未发现 |
| 互斥体 | 未发现 |
| 已验证的扫描器文件名 | 针对 CVE-2026-42533 的 nginx_capture_clobber_scan.py |
| 关键进程 | nginx、nginx: worker process |
| 关键配置文件 | nginx.conf、conf.d/ 下的文件、stream/http 服务器块 |
完整的企业级 CTI 报告可在此获取:
➡️ NGINX_2026_CVE_CTI_Report.md
内容包括:
为 NGINX 打补丁。审计配置指令。关注 worker 崩溃。将边缘代理视为关键基础设施。