Vulnerability GHSA-j3hg-9rp3-5hw9

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 hours ago
October 09, 2026 at 08:57 PM UTC
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
>=1.9.10-0.20260729084040-acb59fdd81db <1.9.10-0.20260901043436-8c9b9a1aff21
>=1.9.10-0.20260729084040-acb59fdd81db <1.9.10-0.20260901043436-8c9b9a1aff21

Summary

Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage

Details

Summary

In Nginx UI versions 2.5.0 through 2.5.x, the node-signature authentication path staged an attacker-controlled request body in a temporary file and synchronized it to disk before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API can provide syntactically valid signature metadata and cause storage and I/O consumption before the request is rejected.

Impact

Concurrent malicious requests can consume temporary filesystem capacity, disk I/O, and request-processing resources, potentially disrupting Nginx UI and other services that share the filesystem. The issue affects availability only; it does not bypass authentication and does not provide confidentiality or integrity impact. Deployment-specific reverse-proxy body limits, filesystem quotas, and concurrency limits may reduce practical impact.

Remediation

Upgrade to Nginx UI 2.6.0 or later. The fix authenticates signed request metadata before staging the body and enforces an application-level streaming size limit with cleanup for rejected requests.

Fix commit: https://github.com/0xJacky/nginx-ui/commit/8c9b9a1aff218ee6c980d047b750e49da3c46796

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 hours ago
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
>=1.9.10-0.20251005005631-6de168c9454 <1.9.10-0.20260904075558-e30e331303fc GHSA-9h23-53f4-q947
>=1.9.10-0.20251005005631-6de168c9454 <1.9.10-0.20260904075558-e30e331303fc GHSA-9h23-53f4-q947
Critical
3 hours ago
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
>=1.9.10-0.20260421071512-7864e378f5cf <1.9.10-0.20260728074146-a467ed652591 GHSA-p393-cf76-4jmr
>=1.9.10-0.20260421071512-7864e378f5cf <1.9.10-0.20260728074146-a467ed652591 GHSA-p393-cf76-4jmr
High Risk
7 hours ago
Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728114330-580585516dd8 GHSA-662p-52hx-cmh2
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728114330-580585516dd8 GHSA-662p-52hx-cmh2
High Risk
7 hours ago
Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074558-95cd21b70814 GHSA-45gv-9wjv-xh7p
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074558-95cd21b70814 GHSA-45gv-9wjv-xh7p
High Risk
7 hours ago
Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-33rr-wq23-g6gg
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-33rr-wq23-g6gg
View all vulnerabilities for these packages

Timeline

Published
3 hours ago
October 09, 2026 at 08:57 PM UTC
Last Modified
2 hours ago
October 09, 2026 at 09:15 PM UTC