Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4111 articles · 197511 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-58661PATCHED
n8n · n8n

n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint

Description

n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota check does not account for files already written to the shared temporary directory, allowing an authenticated user to repeatedly upload files that accumulate on disk until the periodic cleanup runs, potentially exhausting available disk space on the host.

Affected Products

VendorProductVersions
n8nn8nnpm/n8n: >= 2.0.0, < 2.28.0, npm/n8n: < 1.123.58

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
npmn8nGHSA85%

References

  • https://github.com/n8n-io/n8n/security/advisories/GHSA-w867-jm58-p9pv(vendor-advisory)
  • https://www.vulncheck.com/advisories/n8n-disk-space-exhaustion-via-data-table-file-upload-endpoint(third-party-advisory)

Related News (1 articles)

Tier C
VulDB46d ago
CVE-2026-58661 | n8n Data-Table File Upload Endpoint unrestricted upload
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
n8n@2.28.0n8n@1.123.58
CWECWE-770
PublishedJul 10, 2026
Last enriched46d agov2
Trending Score0
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-59259EXP
n8n - Permission Bypass via Expression Parser Mismatch in External Secrets
MEDIUMCVE-2026-59253
n8n - Improper Authorization in Workflow Assignment to Folders
MEDIUMCVE-2026-59254EXP
n8n - External Secrets Disclosure via Workflow Node Expressions
NONECVE-2026-56354EXP
n8n - Cross-Site Scripting and Open Redirect in Form Node
NONECVE-2026-56360
n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: severity
Jul 10, 2026
Patch Available
Jul 10, 2026

Version History

v2
Last enriched 46d ago
v2Tier C46d ago

Updated severity to CRITICAL and noted that no exploit exists.

severity
via VulDB
v146d ago

Initial creation