CVE-2026-107805
Received Received - Intake

Temporary File Staging DoS in Nginx UI

Vulnerability report for CVE-2026-107805, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before rejection. The issue affects availability and does not bypass authentication or provide confidentiality or integrity impact. This issue is fixed in version 2.6.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
0xJacky nginx-ui >= 2.5.0, < 2.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Nginx UI versions 2.5.0 to 2.6.0. It involves the node-signature authentication path staging attacker-controlled request bodies in temporary files before validating their cryptographic signatures. This can consume filesystem space, disk I/O, and processing resources, leading to denial-of-service conditions.

Detection Guidance

Monitor for unusually large temporary files in the nginx-ui staging directory or excessive disk I/O during API requests. Check nginx-ui logs for rejected requests with 413 or 400 status codes indicating oversized payloads.

Impact Analysis

An unauthenticated remote attacker could send malicious requests that fill up temporary storage, slow down disk operations, and consume server resources. This may disrupt Nginx UI and other services sharing the same filesystem, causing downtime or degraded performance.

Mitigation Strategies

Upgrade nginx-ui to version 2.6.0 or later immediately. If upgrading is not possible, restrict network access to the nginx-ui API endpoint and monitor for suspicious large requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107805. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart