Vulnerability library
Security checkMay 13, 2024

Nginx Restriction Bypass via Space Character in URI

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A vulnerability in Nginx allows attackers to bypass security restrictions in specific configurations by exploiting a flaw in request URI processing. When an unescaped space character is followed by certain characters, some security checks on the request URI may be bypassed.

Recommendation

To mitigate this vulnerability, upgrade Nginx to the latest version. As a temporary workaround, apply the following configuration within each server{} block:

  if ($request_uri ~ " ") {
      return 444;
  }

This configuration prevents requests containing spaces from being processed.

References

Could your website be exposed too?

SmartScanner can check your website for Nginx Restriction Bypass via Space Character in URI and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 13, 2024