Origin validation error in nginx-ui - #VU152971
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to origin validation error in the bundled reverse-proxy client identity handling when processing failed login attempts. A remote attacker can submit failed login attempts from different external sources to cause a denial of service.
Existing authenticated sessions are not invalidated.