Download of code without integrity check in nginx-ui - #VU142592

 

Download of code without integrity check in nginx-ui - #VU142592

Published: August 14, 2026


Vulnerability identifier: #VU142592
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to download of code without integrity check in the self-upgrade mechanism when downloading and verifying release binaries and digest files from the same origin. A remote attacker can serve a malicious binary with a matching digest to execute arbitrary code.

User interaction is required to trigger the upgrade process, and exploitation may occur if the download source is compromised or if cleartext HTTP is used for the configured proxy.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.5.0

External References

Related Security Bulletins