PT-2026-96109 · Nginx · Nginx-Ignition

CVE-2026-61629

·

Published

2026-09-21

·

Updated

2026-09-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions nginx ignition versions 2.29.0 through 2.40.0
Description The API server in nginx ignition contains a flaw in its i18nMiddleware function that processes the Accept-Language header. The middleware calls golang.org/x/text/language.ParseAcceptLanguage on the raw header without applying size or shape filters. While a previous guard in the underlying Go library limits the number of - characters, it does not limit characters, which the parser treats as aliases for -.
An unauthenticated attacker can send a specially crafted GET request with a large Accept-Language header containing numerous separators. This triggers quadratic-time behavior in the parser, leading to excessive CPU consumption. For example, a single request can consume approximately 2.4 seconds of server CPU, and ten concurrent attackers can saturate a ten-core system.
Recommendations Update nginx ignition to version 2.40.1. As a temporary mitigation, restrict access to the API server's HTTP listener (default port 8090) to trusted sources only.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61629
GHSA-JR34-H97M-9HPX
GO-2026-6539

Affected Products

Nginx-Ignition