Type Confusion in nginx-ui - #VU152975
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to type confusion in the passkey completion endpoints' shared in-memory cache when processing a client-supplied session identifier. A remote attacker can target a predictable shared cache key and trigger a recovered panic to cause a denial of service.
Remote exploitation is reachable through the unauthenticated passkey-login completion flow when passkeys are enabled.