PT-2026-96109 · Nginx · Nginx-Ignition
CVE-2026-61629
·
Published
2026-09-21
·
Updated
2026-09-28
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
nginx ignition versions 2.29.0 through 2.40.0
Description
The API server in nginx ignition contains a flaw in its
i18nMiddleware function that processes the Accept-Language header. The middleware calls golang.org/x/text/language.ParseAcceptLanguage on the raw header without applying size or shape filters. While a previous guard in the underlying Go library limits the number of - characters, it does not limit characters, which the parser treats as aliases for -.An unauthenticated attacker can send a specially crafted GET request with a large
Accept-Language header containing numerous separators. This triggers quadratic-time behavior in the parser, leading to excessive CPU consumption. For example, a single request can consume approximately 2.4 seconds of server CPU, and ten concurrent attackers can saturate a ten-core system.Recommendations
Update nginx ignition to version 2.40.1.
As a temporary mitigation, restrict access to the API server's HTTP listener (default port 8090) to trusted sources only.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx-Ignition