Junglewise Threat Intelligence

CVE-2026-58661: n8n disk space exhaustion in data-table file upload endpoint

CVE-2026-58661 · Severity: medium · CVSS 4 · Published 2026-07-10

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a popular workflow automation tool used to connect different software services. A vulnerability in its file upload system allows a logged-in user to repeatedly upload files and bypass storage limits. This can lead to the server running out of disk space, potentially causing the entire service to crash or become unavailable for all users.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in n8n's data-table file upload endpoint. The application performs a per-request quota check but fails to account for files already residing in the shared temporary directory from previous requests. An authenticated attacker can exploit this by repeatedly sending upload requests, causing files to accumulate faster than the periodic cleanup process can remove them. This leads to disk space exhaustion on the host system. The issue is fixed in versions 1.123.58 and 2.28.0.

Affected products

  • n8n-io n8n >= 2.0.0, < 2.28.0; < 1.123.58

Timeline

  • 2026-06-24: disclosed: Initial disclosure by reporter
  • 2026-07-22: advisory: GitHub Advisory published

References

Related threats