CVE-2026-107804
Awaiting Analysis Awaiting Analysis - Queue

Reverse Proxy Misconfiguration in Nginx UI Allows IP Spoofing

Vulnerability report for CVE-2026-107804, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
0xJacky nginx-ui >= 2.2.0, < 2.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Nginx UI versions 2.2.0 to 2.6.0. The bundled reverse proxy did not preserve the external client's IP address, causing the backend to treat the local proxy as the client. This led to IP allowlist checks being bypassed and failed login attempts being aggregated under a single loopback address, enabling attackers to trigger shared temporary login bans.

Detection Guidance

Check if your nginx-ui version is between 2.2.0 and 2.6.0. Review proxy logs for repeated failed login attempts from loopback addresses (127.0.0.1) that may indicate the issue. Inspect network traffic for forwarded requests not properly preserving client IPs.

Impact Analysis

An unauthenticated attacker could trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This could deny access to other users until the ban expires, primarily affecting availability through potential denial-of-service via login lockouts.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by enabling unauthorized access to management endpoints through IP allowlist bypasses. Failed login attempts triggering shared bans may also disrupt legitimate user access, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade nginx-ui to version 2.6.0 or later to address the trusted proxy and IP handling issues. Ensure trusted proxy settings are configured in authentication settings to preserve client IPs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107804. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart