OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-61629

HIGH · CVSS 7.5 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Nginx Ignition versions 2.29.0 through 2.40.0 are vulnerable to a denial-of-service attack due to the gin i18n middleware's inefficient handling of malformed `Accept-Language` headers, which can lead to significant CPU resource exhaustion. Attackers can exploit this vulnerability with unauthenticated GET requests, potentially saturating server resources and degrading service availability. Organizations using affected Nginx Ignition versions should prioritize upgrading to version 2.40.1 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61629
Severity
HIGH
CVSS
7.5
EPSS
0.42%
Nginx

Original NVD Description

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape filter. The underlying parser has quadratic-time behaviour on long lists of malformed language tags. The CVE-2022-32149 guard that golang.org/x/text added in v0.3.8 caps the number of `-` characters in the input at 1000, but it does not cap `_` characters even though the parser's internal scanner aliases `_` to `-` before parsing. A single unauthenticated GET request with an `Accept-Language` header built out of `_` separators burns about 2.4 seconds of server CPU on the host running nginx-ignition; ten concurrent attackers saturate a ten-core box for the duration of the attack while consuming ~10 MiB/s of upstream bandwidth. Version 2.40.1 fixes this issue.