Impact
A flaw in the nginx‑ui node‑signature authentication chain lets an unauthenticated remote client submit syntactically sound signature data so that the service temporarily stages the request body on disk before rejecting it. This causes arbitrary consumption of filesystem space, disk I/O, and CPU resources, leading to a complete denial of service but without compromising authentication, confidentiality, or integrity.
Affected Systems
The vulnerability exists in the 0xJacky nginx‑ui product for all releases from version 2.5.0 up to, but not including, the fixed release 2.6.0. Users should upgrade to 2.6.0 or later to eliminate the issue.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as High severity. With no EPSS score available, the exact exploitation likelihood is uncertain, and the vulnerability is not listed in the CISA KEV catalog. Attackers can remotely exploit the path by targeting the publicly reachable API endpoint with crafted signature metadata, making the risk significant for exposed deployments.
OpenCVE Enrichment