CVE-2026-107804 Nginx UI 反向代理身份识别不当漏洞
影响未认证攻击者可触发共享登录封禁,导致合法用户被拒绝登录
Nginx UI 是 Nginx 的 Web 管理界面。2.2.0 至 2.6.0 版本内置的反向代理未配置 Gin 的受信代理,导致后端无法获取真实外部客户端 IP,管理请求被误判为来自回环地址。该问题已在 2.6.0 修复。
影响范围
Nginx UI 2.2.0 至 2.6.0 之前的版本;2.6.0 已修复。
漏洞详情
由于反向代理未设置受信代理配置,Gin 后端将所有请求来源识别为回环地址。管理请求因此可绕过 IP 白名单中的回环例外(仍需有效凭据),而来自不同外部客户端的失败登录也被归为同一回环地址,从而触发共享的临时登录封禁。
利用条件与风险
利用无需认证,攻击者可通过多次失败登录触发共享封禁,造成密码或 OTP 认证的合法用户被临时拒绝登录;但不会使已有会话失效,且管理接口仍需有效凭据。
修复建议
升级至 Nginx UI 2.6.0 或更高版本;临时可限制外部访问来源或调整反向代理的受信代理配置以正确传递客户端 IP。
Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.