CVE-2026-107805

Source
https://cve.org/CVERecord?id=CVE-2026-107805
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107805.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107805
Aliases
Published
2026-10-09T14:50:58Z
Modified
2026-10-11T02:46:38Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
Details

Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before rejection. The issue affects availability and does not bypass authentication or provide confidentiality or integrity impact. This issue is fixed in version 2.6.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107805.json"
}
References

Affected packages

Git / github.com/0xjacky/nginx-ui

Affected ranges

Type
GIT
Repo
https://github.com/0xjacky/nginx-ui
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.5.0"
        },
        {
            "fixed": "2.6.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.5.0
v2.5.1
v2.5.10
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107805.json"