n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota check does not account for files already written to the shared temporary directory, allowing an authenticated user to repeatedly upload files that accumulate on disk until the periodic cleanup runs, potentially exhausting available disk space on the host.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-w867-jm58-p9pv | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-disk-space-exhaustion-via-data-table-file-upload-endpoint | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 16:57
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
N8n
N8n n8n |
|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-w867-jm58-p9pv - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/n8n-disk-space-exhaustion-via-data-table-file-upload-endpoint - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:* cpe:2.3:a:n8n:n8n:*:*:*:*:community:node.js:*:* |
10 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 15:16
Updated : 2026-07-13 16:57
NVD link : CVE-2026-58661
Mitre link : CVE-2026-58661
CVE.ORG link : CVE-2026-58661
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
