CVE-2026-107805 Nginx UI 节点签名认证资源耗尽漏洞
影响未认证远程攻击者可耗尽磁盘与请求处理资源,导致服务不可用
Nginx UI 是 Nginx 的 Web 管理界面。在 2.5.0 至 2.6.0 之前版本中,节点签名认证路径会先将攻击者可控的请求体写入临时文件并同步落盘,之后才校验请求体摘要与密码学签名。未认证远程客户端只要提供语法合法的签名元数据,就能在请求被拒绝前持续消耗临时文件系统容量、磁盘 I/O 与请求处理资源。
影响范围
Nginx UI 2.5.0 起至 2.6.0 之前的版本;2.6.0 已修复。
漏洞详情
漏洞类型为资源耗尽(不受控资源消耗)。成因是认证流程顺序不当:先暂存并同步请求体,再验证摘要与签名,导致未通过校验的请求也已完成磁盘写入。攻击者无需有效凭据,只需构造语法合法的签名元数据并发送较大请求体,即可反复触发临时文件写入与同步操作。该问题仅影响可用性,不绕过认证,也不造成机密性或完整性影响。
利用条件与风险
利用前提是攻击者能访问该 API 接口,无需认证。实战中可通过大量或大体积请求持续占用磁盘空间与 I/O,造成服务响应缓慢甚至不可用,属于拒绝服务类风险。
修复建议
官方已在 2.6.0 版本修复,建议升级至 2.6.0 或更高版本。临时缓解措施包括限制该 API 的网络访问来源、对请求体大小与请求速率进行限制,并监控临时目录磁盘占用;暂无其他公开信息。
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before rejection. The issue affects availability and does not bypass authentication or provide confidentiality or integrity impact. This issue is fixed in version 2.6.0.