Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attacker able to alter both responses can supply a malicious executable and matching digest. An operator-triggered upgrade is required, and the application installs and runs the attacker-controlled code in the Nginx UI process context on the next upgrade. This issue is fixed in version 2.5.0.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-662p-52hx-cmh2 | Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
0xjacky
0xjacky nginx-ui |
|
| Vendors & Products |
0xjacky
0xjacky nginx-ui |
Fri, 09 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attacker able to alter both responses can supply a malicious executable and matching digest. An operator-triggered upgrade is required, and the application installs and runs the attacker-controlled code in the Nginx UI process context on the next upgrade. This issue is fixed in version 2.5.0. | |
| Title | Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T15:41:04.107Z
Reserved: 2026-10-08T21:23:59.822Z
Link: CVE-2026-107812
No data.
Status : Awaiting Analysis
Published: 2026-10-09T16:17:25.847
Modified: 2026-10-09T16:38:57.820
Link: CVE-2026-107812
No data.
OpenCVE Enrichment
Updated: 2026-10-09T17:30:08Z
Weaknesses
Github GHSA