目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-66835— Apache HTTP Server mod_auth 目录保护绕过漏洞

一分钟漏洞结论

影响对象
Erlang OTP
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Erlang/OTP 中的 inets httpd 存在路径等价性(Path Equivalence)漏洞,使得远程未认证的攻击者可以通过在请求路径前添加一个额外的斜杠,读取位于 保护目录内的文件。 具体机制如下: 使用 对请求 URI 进行规范化处理。该过程执行了 RFC 3986 中定义的“点段”(dot-segment)移除,但不会合并空路径段,因此连续的重复斜杠(如 )会被保留。 将文档根目录与规范化后的 URI 拼接成完整路径。 通过将被配置的保护目录路径作为未锚定的正则表达式在拼接后的路径上进行匹配,以

CVSS 8.2 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-66835 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
httpd mod_auth directory protection bypassed by a doubled slash in the request path
来源: CVE Program / CVE List V5
Vulnerability Description
Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986 dot-segment removal but does not collapse empty path segments, so a doubled slash survives. mod_alias:real_name/3 concatenates the document root with that URI, and mod_auth:secret_path/3 then decides whether the result lies inside a protected directory block by running the configured directory path as an unanchored regular expression against it. The doubled slash breaks the contiguous substring the regex needs, so the request is treated as unprotected and no authentication challenge is issued, while mod_get opens the same path and the operating system collapses the doubled slash and returns the protected file. The same path mismatch also evades the per-path accounting in mod_security. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
路径等价:’//multiple/leading/slash’
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Erlang OTP 17.0 ~ 27.3.4.17 cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 5.10 ~ 9.3.2.7 cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 84adefa331c4159d432d22840663c38f155cd4c1 ~ * cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-66835 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-66835 的情报信息

登录查看更多情报信息。

CVE-2026-66835 其他参考 (6)

同批安全公告 · Erlang · 2026-09-01 · 共 16 条

CVE-2026-71380 8.7 HIGH Apache HTTP Server 请求体接收超时缺失
CVE-2026-70399 8.7 HIGH Apache HTTP Server 最大连接数限制失效漏洞
CVE-2026-74835 8.7 HIGH Nginx HTTPD 内存耗尽漏洞
CVE-2026-69664 8.7 HIGH Apache HTTP Server 请求处理器因畸形块大小导致挂起漏洞
CVE-2026-66357 8.3 HIGH inets/httpd 请求走私漏洞
CVE-2026-73812 8.3 HIGH IIS 与 Apache httpd 请求走私漏洞
CVE-2026-73276 8.3 HIGH inetd, httpd 请求走私漏洞
CVE-2026-55951 8.2 HIGH libcurl HTTP客户端响应头内存耗尽漏洞
CVE-2026-75538 8.2 HIGH Erlang/OTP inet驱动 整数溢出漏洞
CVE-2026-73270 8.2 HIGH Apache httpd mod_auth 路径大小写目录保护绕过漏洞
CVE-2026-59696 6.9 MEDIUM URI端口分量整数转换前未限制
CVE-2026-71562 6.3 MEDIUM libcurl httpc 整数转换越界漏洞
CVE-2026-70405 6.3 MEDIUM SNMP BER INTEGER解码器整数长度无限制
CVE-2026-70409 6.3 MEDIUM eldap 整数溢出漏洞
CVE-2026-74994 6.0 MEDIUM httpd mod_auth 认证绕过漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-66835

暂无评论


发表评论