Junglewise Threat Intelligence

n8n disk space exhaustion in data-table file upload endpoint

Severity: medium · CVSS 4.3 · Published 2026-07-10

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool used to connect different software services. A vulnerability in its file upload system allows a logged-in user to fill up the server's storage by repeatedly uploading files. This can lead to a complete service outage or system instability as the server runs out of disk space.

Technical details

n8n contains a resource exhaustion vulnerability (CWE-770) in its data-table file upload endpoint. The vulnerability exists because the per-request quota check fails to account for files already present in the shared temporary directory. An authenticated attacker can exploit this by repeatedly uploading files that bypass individual limits but aggregate on the host's disk. This accumulation continues until the next periodic cleanup cycle, potentially exhausting all available disk space and causing a denial-of-service (DoS). The issue is patched in versions 1.123.58 and 2.28.0.

Affected products

  • n8n n8n < 1.123.58, 2.0.0 to < 2.28.0

Timeline

  • 2026-06-24: advisory: Original advisory GHSA-w867-jm58-p9pv published
  • 2026-07-10: disclosed: CVE-2026-58661 assigned and published to NVD
  • 2026-07-22: other: Duplicate advisory GHSA-2vww-6p9h-5g8j withdrawn

References

Related threats