CVE-2026-107805: Unauthenticated Storage Exhaustion in Nginx UI Node Authentication
Vulnerability ID: CVE-2026-107805
CVSS Score: 7.5
Published: 2026-10-09
Nginx UI versions 2.5.0 through 2.5.10 contain an uncontrolled resource consumption vulnerability in the node authentication handler. Unauthenticated remote attackers can exhaust host disk storage and I/O resources by submitting large HTTP request bodies to node-signature endpoints prior to cryptographic signature validation.
TL;DR
Nginx UI stages incoming request bodies to temporary disk storage before verifying node signatures. Unauthenticated remote attackers can exhaust disk space and cause a denial of service.
Technical Details
- CWE ID: CWE-400
- Attack Vector: Network (AV:N)
- CVSS Score: 7.5 (High)
- EPSS Score: Not Listed
- Impact: Denial of Service (Storage & I/O Exhaustion)
- Exploit Status: No Public Exploit Available
- CISA KEV Status: Not Listed
Affected Systems
- Nginx UI versions >= 2.5.0, < 2.6.0
-
nginx-ui: >= 2.5.0, < 2.6.0 (Fixed in:
2.6.0)
Code Analysis
Commit: 8c9b9a1
fix(node): bound signed request body staging
Mitigation Strategies
- Upgrade Nginx UI to version 2.6.0 or higher.
- Enforce request body size limits at the reverse proxy layer.
- Isolate host temporary storage (/tmp) using dedicated partitions or tmpfs mounts with capacity limits.
- Restrict network access to node authentication interfaces using firewalls or security groups.
Remediation Steps:
- Deploy Nginx UI version v2.6.0 or later to affected management instances.
- Configure client_max_body_size in upstream Nginx reverse proxies to restrict unauthenticated payload sizes.
- Apply network firewall policies restricting node-signature endpoint access to trusted node IP ranges.
References
- GitHub Security Advisory GHSA-j3hg-9rp3-5hw9
- Official Fix Commit in 0xJacky/nginx-ui
- Nginx UI Release v2.6.0
- NVD CVE-2026-107805 Detail
- CVE Record CVE-2026-107805
Read the full report for CVE-2026-107805 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)