Server-Side Request Forgery (SSRF) in nginx-ui - #VU152973
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to perform server-side requests to attacker-selected network targets.
The vulnerability exists due to improper access control in the stored health-check mutation routes when saving health-check configurations in Demo mode. A remote user can save a health-check target to cause the server to perform health checks to attacker-selected network destinations.
Health-check results expose derived status information and content-match decisions, but target response bodies are not returned.