Vulnerability GHSA-9h23-53f4-q947

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
October 09, 2026 at 08:57 PM UTC
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
>=1.9.10-0.20251005005631-6de168c9454 <1.9.10-0.20260904075558-e30e331303fc
>=1.9.10-0.20251005005631-6de168c9454 <1.9.10-0.20260904075558-e30e331303fc

Summary

Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout

Details

Summary

In Nginx UI versions 2.2.0 through 2.5.x, the official bundled reverse-proxy topology did not preserve the external client identity used by Gin. The backend treated the local proxy peer as the client because no trusted proxy was configured, while the proxy supplied the actual address in forwarding headers.

Impact

This has two distinct effects in bundled-proxy deployments:

  • IP allowlist enforcement: management API requests forwarded by the bundled proxy were identified as loopback and could pass the loopback exception even when the external source was not in the configured allowlist. Protected management operations still required valid credentials; this did not grant unauthenticated administrator access.
  • Login availability: failed login attempts from different external sources were attributed to one loopback address. An unauthenticated attacker could therefore trigger the shared temporary login-ban threshold and deny password or OTP login to other users behind the proxy until the ban expired. Existing authenticated sessions were not invalidated.

Remediation

Upgrade to Nginx UI 2.6.0 or later. The fix explicitly trusts only the intended bundled proxy, validates configured trusted proxies, uses the resolved client address consistently, and fails closed when an IP allowlist is enabled but the client address is invalid.

Fix commit: https://github.com/0xJacky/nginx-ui/commit/e30e331303fc21cf077a2bea724bd79e66892eaf

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 hours ago
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
>=1.9.10-0.20260729084040-acb59fdd81db <1.9.10-0.20260901043436-8c9b9a1aff21 GHSA-j3hg-9rp3-5hw9
>=1.9.10-0.20260729084040-acb59fdd81db <1.9.10-0.20260901043436-8c9b9a1aff21 GHSA-j3hg-9rp3-5hw9
Critical
3 hours ago
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
>=1.9.10-0.20260421071512-7864e378f5cf <1.9.10-0.20260728074146-a467ed652591 GHSA-p393-cf76-4jmr
>=1.9.10-0.20260421071512-7864e378f5cf <1.9.10-0.20260728074146-a467ed652591 GHSA-p393-cf76-4jmr
High Risk
6 hours ago
Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728114330-580585516dd8 GHSA-662p-52hx-cmh2
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728114330-580585516dd8 GHSA-662p-52hx-cmh2
High Risk
6 hours ago
Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074558-95cd21b70814 GHSA-45gv-9wjv-xh7p
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074558-95cd21b70814 GHSA-45gv-9wjv-xh7p
High Risk
6 hours ago
Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-33rr-wq23-g6gg
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-33rr-wq23-g6gg
View all vulnerabilities for these packages

Timeline

Published
3 hours ago
October 09, 2026 at 08:57 PM UTC
Last Modified
2 hours ago
October 09, 2026 at 09:15 PM UTC