Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107805— Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage

Quick assessment

Affected
0xJacky nginx-ui
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nginx UI 是 Nginx Web 服务器的 Web 用户界面。在版本 2.5.0 至 2.6.0 之间,节点签名(node-signature)认证路径在执行请求体摘要验证和密码学签名验证之前,会先将攻击者可控的请求体内容暂存到临时文件中,并同步该文件。攻击者无需认证即可访问 API,并提供语法上有效的签名元数据,从而在请求被拒绝之前,大量消耗临时文件系统容量、磁盘 I/O 资源以及请求处理资源。此漏洞影响服务的可用性,但不会绕过认证机制,也不会对数据的机密性或完整性造成负面影响。该问题已在版本 2.6.0

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107805

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
Source: CVE Program / CVE List V5
Vulnerability Description
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before rejection. The issue affects availability and does not bypass authentication or provide confidentiality or integrity impact. This issue is fixed in version 2.6.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
0xJacky nginx-ui >= 2.5.0, < 2.6.0 -

II. Public POCs for CVE-2026-107805

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107805

请登录查看更多情报信息。

Other References for CVE-2026-107805 (3)

Same Patch Batch · 0xJacky · 2026-10-09 · 10 CVEs total

CVE-2026-107806 9.4 CRITICAL Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
CVE-2026-107807 8.8 HIGH Nginx UI: Node Secret Credential Exposure via URL Query Parameter
CVE-2026-107809 8.8 HIGH Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs
CVE-2026-107811 8.8 HIGH 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation
CVE-2026-107813 8.8 HIGH Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in
CVE-2026-107808 8.1 HIGH Nginx UI: Authentication bypass: password login does not enforce a passkey-only second fac
CVE-2026-107810 8.1 HIGH Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path b
CVE-2026-107812 7.5 HIGH Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE
CVE-2026-107804 5.3 MEDIUM Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout

IV. Related Vulnerabilities

V. Comments for CVE-2026-107805

No comments yet


Leave a comment