Resource exhaustion in nginx-ui - #VU152972
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the node-signature authentication path when staging attacker-controlled request bodies before validating their digest and cryptographic signature. A remote attacker can send concurrent requests with syntactically valid signature metadata to cause a denial of service.
Temporary filesystem capacity, disk I/O, and request-processing resources can be consumed before the requests are rejected.