Unauthenticated Denial of Service via Temporary File Exhaustion in Nginx UI
An unauthenticated remote attacker can exploit CVE-2026-107805 in Nginx UI by sending malicious requests that trigger premature staging of large, unsigned request bodies, leading to disk space and I/O exhaustion.
CVE search metadata
CVE search record: CVE-2026-107805. Severity: high. CVSS: 7.5. KEV: no. Product: Nginx UI (2.5.0-2.5.x), Nginx-UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728091109-0ecbd106c37b, 2.4.2), Nginx UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728074433-a3999bd78a3b), Nginx UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728074146-a467ed652591). Brief: Unauthenticated Denial of Service via Temporary File Exhaustion in Nginx UI. Brief link: https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-dos/
What's new
- 1. added coverage for Nginx UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728074146-a467ed652591) Oct 9, 21:28 via ghsa
- 2. added coverage for Nginx UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728074433-a3999bd78a3b) Oct 9, 21:28 via ghsa
- 3. added coverage for Nginx-UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728091109-0ecbd106c37b, 2.4.2) Oct 9, 21:28 via ghsa
Nginx UI versions 2.5.0 through 2.5.x are vulnerable to a high-severity denial-of-service condition involving improper request processing. The application's node-signature authentication logic incorrectly stages the body of incoming requests to temporary files on disk before validating the associated cryptographic signature or body digest.
An unauthenticated remote attacker capable of reaching the Nginx UI API can initiate requests containing syntactically correct signature metadata but arbitrary, large body payloads. Because the application processes these requests and commits them to temporary storage prior to authentication, a stream of concurrent, malicious requests can consume system-level disk capacity, saturate I/O throughput, and exhaust request-processing threads. This behavior disrupts the availability of Nginx UI and may impact other services residing on the same infrastructure. The vulnerability is strictly an availability concern and does not facilitate unauthorized access, data confidentiality loss, or integrity compromise.
Impact
The vulnerability allows for resource exhaustion, leading to a denial of service. The impact is primarily on system availability, where excessive concurrent requests can lead to full temporary partitions or I/O starvation. The degree of impact depends heavily on environmental factors such as available disk quotas, configured reverse-proxy body limits, and server-side concurrency constraints.
Recommendation
Prioritize upgrading to Nginx UI 2.6.0 or later to mitigate the vulnerability. The patch introduces a check to authenticate request metadata prior to staging and implements improved request body streaming with size constraints and automatic cleanup for discarded requests.
- Upgrade Nginx UI to 2.6.0 or later immediately.
- Review temporary filesystem usage patterns to detect spikes in
/tmpor designated staging directories associated with Nginx UI. - Implement application-level request size limits in front-end reverse proxies (e.g., standard Nginx or HAProxy) to prevent oversized payloads from reaching the application API.
- Configure system-level disk quotas for the service account running Nginx UI to contain the impact of storage exhaustion.
Immediate actions
Upgrade Nginx UI to version 2.6.0 or later.
Mitigations
Configure reverse proxy request body limits.
CVE-2026-107805