Impact
Nginx UI’s bundled reverse proxy fails to preserve the external client’s IP address, resulting in requests appearing to originate from the loopback interface. Because the IP allowlist configuration only excludes the loopback interface, an attacker can send management‑related traffic from any external address that is treated as permitted. In addition, authentication failures from distinct external clients are consolidated under the loopback address, allowing an unauthenticated user to provoke a shared temporary login ban for password or OTP authentication. The attacker therefore gains indirect access to bypass IP‑based restrictions and can cause legitimate users to be denied service through lockout.
Affected Systems
The vulnerability is present in the 0xJacky:nginx-ui package, specifically in all releases from version 2.2.0 up to and excluding 2.6.0. Version 2.6.0 introduces the fix that correctly preserves external IP addresses and prevents the shared lockout issue.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is remote, as an external adversary can send requests to the management interface from arbitrary IPs and trigger the lockout mechanism without needing initial authentication or valid credentials. Exploitation requires the existence of a working authentication system that logs failure attempts, but the attacker does not need administrative privileges.
OpenCVE Enrichment