CVE-2026-107807 PUBLISHED

Nginx UI: Node Secret Credential Exposure via URL Query Parameter

Assigner: GitHub_M
Reserved: 08.10.2026 Published: 09.10.2026 Updated: 09.10.2026

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment environment data. A party that obtains the secret can bypass normal password, JWT, session, and second-factor checks and obtain persistent administrative API access, including access to configuration and secret material. This issue is fixed in version 2.5.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor 0xJacky
Product nginx-ui
Versions
  • Version >= 2.0.0, < 2.5.0 is affected

References

Problem Types

  • CWE-312: Cleartext Storage of Sensitive Information CWE
  • CWE-598: Use of GET Request Method With Sensitive Query Strings CWE