OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-107805: Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage

GitHub Advisories · officialPublished Oct 9, 2026Risk 37/100

## Summary In Nginx UI versions 2.5.0 through 2.5.x, the node-signature authentication path staged an attacker-controlled request body in a temporary file and synchronized it to disk before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API can provide syntactically valid signature metadata and cause storage and I/O consumption before the request is rejected. ## Impact Concurrent malicious requests can consume temporary filesystem capacity, disk I/O, and request-processing resources, potentially disrupting Nginx UI and other services that share the filesystem. The issue affects availability only; it does not bypass authentication and does not provide confidentiality or integrity impact. Deployment-specific reverse-proxy body limits, filesystem quotas, and concurrency limits may reduce practical impact. ## Remediation Upgrade to Nginx UI 2.6.0 or later. The fix authenticates signed request metadata before staging the body and enforces an application-level streaming size limit with cleanup for rejected requests. Fix commit: https://github.com/0xJacky/nginx-ui/commit/8c9b9a1aff218ee6c980d047b750e49da3c46796

Upgrade affected packages to a patched version: github.com/0xJacky/Nginx-UI 1.9.10-0.20260901043436-8c9b9a1aff21.

Vendor
Not specified
Product
github.com/0xJacky/Nginx-UI
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source