NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
高危 CVSS 8.1
摘要
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sendin…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
- :
数据来源
- NVD DATABASE
原始链接
- https://my.f5.com/manage/s/article/K000161377 Mitigation
- http://www.openwall.com/lists/oss-security/2026/05/22/14 Mailing List
- https://lists.debian.org/debian-lts-announce/2026/06/msg00023.html Mailing List
- https://access.redhat.com/errata/RHSA-2026:20351 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28212 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28921 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:28973 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29151 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:29874 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33313 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:44481 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-9256 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2480746 Issue Tracking
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9256.json Third Party Advisory
时间线
- nvd_ingest NVD