PT-2026-108934 · Nginx-Ui · Nginx-Ui
CVE-2026-107805
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Nginx UI versions 2.5.0 through 2.5.x
Description
The node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it to disk before validating the body digest and cryptographic signature. An unauthenticated remote client capable of reaching the API and providing syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before the request is rejected. This issue affects availability and may disrupt Nginx UI and other services sharing the same filesystem, though it does not bypass authentication or impact confidentiality and integrity.
Recommendations
Upgrade to Nginx UI version 2.6.0 or later.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx-Ui