Disclosure summary
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before rejection. The issue affects availability and does not bypass authentication or provide confidentiality or integrity impact. This issue is fixed in version 2.6.0.
Source-reported weakness categories
CWE-400
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-j3hg-9rp3-5hw9
Open original source · Updated Oct 09, 2026
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/0xJacky/Nginx-UI | >= 1.9.10-0.20260729084040-acb59fdd81db, < 1.9.10-0.20260901043436-8c9b9a1aff21 | 1.9.10-0.20260901043436-8c9b9a1aff21 |
NIST National Vulnerability Database · NVD-CVE-2026-107805
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-09T11:17:09-04:00
MODIFIED 2026-10-09T12:38:57-04:00
INGESTED 2026-10-10T20:55:12-04:00