CVE-2026-107804: Client IP Resolution Flaw & Authentication Lockout in Nginx UI
Vulnerability ID: CVE-2026-107804
CVSS Score: 5.3
Published: 2026-10-09
Nginx UI versions 2.2.0 through 2.5.10 fail to properly configure Gin framework trusted proxies when deployed behind a reverse proxy. This causes all incoming HTTP requests to be attributed to the loopback IP (127.0.0.1), enabling IP allowlist bypass and global authentication lockouts.
TL;DR
Unconfigured trusted reverse proxies in Nginx UI cause client IP misattribution to loopback, allowing IP white-list bypass and authentication lockout DoS.
Technical Details
- CWE ID: CWE-346 (Origin Validation Error)
- Attack Vector: Network (AV:N)
- CVSS v3.1: 5.3 (Medium)
- EPSS Score: N/A
- Impact: IP Allowlist Bypass, Denial of Service
- Exploit Status: No public PoC available
- CISA KEV Status: Not Listed
Affected Systems
- Nginx UI versions 2.2.0 through 2.5.10
- Nginx UI Docker containers running behind bundled or external reverse proxies
Mitigation Strategies
- Upgrade Nginx UI to version 2.6.0 or later.
- Configure TrustedProxies in app.ini or NGINX_UI_AUTH_TRUSTED_PROXIES environment variable.
- Avoid setting TrustedProxies to wildcard ranges like 0.0.0.0/0 to prevent client IP spoofing.
Remediation Steps:
- Pull the latest container image via 'docker compose pull nginx-ui' and recreate the service.
- Inspect app.ini or container variables to confirm TrustedProxies matches only valid upstream reverse proxy addresses.
- Restart Nginx UI to ensure Gin initializes SetTrustedProxies correctly on startup.
Read the full report for CVE-2026-107804 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)