PT-2026-108934 · Nginx-Ui · Nginx-Ui

CVE-2026-107805

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nginx UI versions 2.5.0 through 2.5.x
Description The node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it to disk before validating the body digest and cryptographic signature. An unauthenticated remote client capable of reaching the API and providing syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before the request is rejected. This issue affects availability and may disrupt Nginx UI and other services sharing the same filesystem, though it does not bypass authentication or impact confidentiality and integrity.
Recommendations Upgrade to Nginx UI version 2.6.0 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107805
GHSA-J3HG-9RP3-5HW9

Affected Products

Nginx-Ui