Disclosure summary
Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.
Source-reported weakness categories
CWE-346
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-9h23-53f4-q947
Open original source · Updated Oct 09, 2026
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/0xJacky/Nginx-UI | >= 1.9.10-0.20251005005631-6de168c9454, < 1.9.10-0.20260904075558-e30e331303fc | 1.9.10-0.20260904075558-e30e331303fc |
NIST National Vulnerability Database · NVD-CVE-2026-107804
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-09T11:17:09-04:00
MODIFIED 2026-10-09T12:38:57-04:00
INGESTED 2026-10-10T20:55:12-04:00