Download of code without integrity check in nginx-ui - #VU142592
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to download of code without integrity check in the self-upgrade mechanism when downloading and verifying release binaries and digest files from the same origin. A remote attacker can serve a malicious binary with a matching digest to execute arbitrary code.
User interaction is required to trigger the upgrade process, and exploitation may occur if the download source is compromised or if cleartext HTTP is used for the configured proxy.