DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107804: CVE-2026-107804: Client IP Resolution Flaw & Authentication Lockout in Nginx UI

CVE-2026-107804: Client IP Resolution Flaw & Authentication Lockout in Nginx UI

Vulnerability ID: CVE-2026-107804
CVSS Score: 5.3
Published: 2026-10-09

Nginx UI versions 2.2.0 through 2.5.10 fail to properly configure Gin framework trusted proxies when deployed behind a reverse proxy. This causes all incoming HTTP requests to be attributed to the loopback IP (127.0.0.1), enabling IP allowlist bypass and global authentication lockouts.

TL;DR

Unconfigured trusted reverse proxies in Nginx UI cause client IP misattribution to loopback, allowing IP white-list bypass and authentication lockout DoS.


Technical Details

  • CWE ID: CWE-346 (Origin Validation Error)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1: 5.3 (Medium)
  • EPSS Score: N/A
  • Impact: IP Allowlist Bypass, Denial of Service
  • Exploit Status: No public PoC available
  • CISA KEV Status: Not Listed

Affected Systems

  • Nginx UI versions 2.2.0 through 2.5.10
  • Nginx UI Docker containers running behind bundled or external reverse proxies

Mitigation Strategies

  • Upgrade Nginx UI to version 2.6.0 or later.
  • Configure TrustedProxies in app.ini or NGINX_UI_AUTH_TRUSTED_PROXIES environment variable.
  • Avoid setting TrustedProxies to wildcard ranges like 0.0.0.0/0 to prevent client IP spoofing.

Remediation Steps:

  1. Pull the latest container image via 'docker compose pull nginx-ui' and recreate the service.
  2. Inspect app.ini or container variables to confirm TrustedProxies matches only valid upstream reverse proxy addresses.
  3. Restart Nginx UI to ensure Gin initializes SetTrustedProxies correctly on startup.

Read the full report for CVE-2026-107804 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)