Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-86081

CVE-2026-86081: n8n Workflow Automation Platform DoS Vulnerability

CVE-2026-86081 is a denial of service flaw in n8n workflow automation platform caused by catastrophic backtracking in Git node operations. Authenticated editors can freeze instances with one execution. This article covers technical details, affected versions, impact analysis, and mitigation steps.

Updated:

CVE-2026-86081 Overview

CVE-2026-86081 is a Regular Expression Denial of Service (ReDoS) vulnerability in n8n, an open source workflow automation platform. The flaw resides in the Git node clone operation, which matches an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern ^(./).git(/.)$ allows catastrophic backtracking and runs synchronously in the main n8n process. An authenticated workflow editor can freeze an entire n8n instance with a single workflow execution. The issue is tracked as [CWE-1333] and is fixed in versions 1.123.76, 2.37.7, and 2.38.2.

Critical Impact

An authenticated workflow editor can freeze the main n8n process by triggering catastrophic regex backtracking through a crafted Git node clone destination path.

Affected Products

  • n8n versions prior to 1.123.76
  • n8n versions prior to 2.37.7
  • n8n versions prior to 2.38.2

Discovery Timeline

  • 2026-09-08 - CVE-2026-86081 published to NVD
  • 2026-09-09 - Last updated in NVD database

Technical Details for CVE-2026-86081

Vulnerability Analysis

The vulnerability originates in the default file path blocklist regular expression declared in packages/@n8n/config/src/configs/security.config.ts. When the Git node performs a clone operation, n8n validates the destination path against this pattern. Because the regex contains ambiguous quantifiers, matching an adversarially crafted input causes exponential backtracking in the JavaScript regex engine.

The matching runs synchronously on the Node.js main event loop. A single unresponsive regex evaluation blocks all concurrent workflow executions, API requests, and UI interactions for the entire n8n instance. The result is a full application-level denial of service triggered by one workflow run.

Root Cause

The root cause is an insecure regular expression, ^(./).git(/.)$, used to enforce the N8N_BLOCK_FILE_PATTERNS security control. The nested repetition permits many overlapping match paths, satisfying the classic ReDoS condition described by [CWE-1333]. Because the check is performed inline with request handling, the CPU cost of backtracking directly consumes the process thread.

Attack Vector

Exploitation requires an authenticated user with permission to create or edit workflows containing a Git node. The attacker configures the Git clone destination path to a value engineered to force catastrophic backtracking against the vulnerable pattern. Executing the workflow triggers the synchronous regex evaluation, hanging the n8n main process until the operation is externally terminated.

No verified public proof-of-concept code is available. Technical details are documented in the GitHub Security Advisory GHSA-j535-v25q-vx3q.

Detection Methods for CVE-2026-86081

Indicators of Compromise

  • Sustained 100% CPU utilization on a single Node.js worker tied to the n8n process without a corresponding increase in request volume.
  • Workflow executions involving a Git node that remain in a running state indefinitely or exceed configured execution timeouts.
  • Loss of responsiveness in the n8n editor UI and REST API concurrent with a Git node clone execution.
  • Workflow audit entries showing recently created or modified Git nodes authored by non-administrative editors.

Detection Strategies

  • Inspect workflow definitions for Git nodes whose destinationPath parameter contains unusually long strings, repeated character sequences, or patterns designed to defeat the ^(./).git(/.)$ regex.
  • Correlate n8n process CPU spikes with the execution IDs of workflows containing Git operations to isolate suspicious runs.
  • Monitor for authenticated API calls to workflow execution endpoints that immediately precede event loop stalls.

Monitoring Recommendations

  • Enable Node.js event loop lag metrics and alert when lag exceeds an operational baseline for the n8n container or process.
  • Ship n8n application logs and workflow execution telemetry to a centralized analytics platform for correlation with host CPU metrics.
  • Track creation and modification events for workflows containing Git nodes, especially by non-administrator accounts.

How to Mitigate CVE-2026-86081

Immediate Actions Required

  • Upgrade n8n to version 1.123.76, 2.37.7, or 2.38.2 depending on your release channel.
  • Audit user permissions and remove workflow editing rights from accounts that do not require them.
  • Review existing workflows for Git nodes with suspicious destination path configurations and disable them until validated.

Patch Information

The vendor has published fixes in the following releases: n8n 1.123.76, n8n 2.37.7, and n8n 2.38.2. Full technical details are provided in GitHub Security Advisory GHSA-j535-v25q-vx3q.

Workarounds

  • Override the default N8N_BLOCK_FILE_PATTERNS environment variable with a linear-time regex that avoids nested quantifiers if immediate patching is not possible.
  • Restrict use of the Git node to a small set of trusted operators through role-based access controls.
  • Place n8n behind an execution timeout or process supervisor that terminates worker processes exceeding a bounded CPU budget.
bash
# Configuration example: override the vulnerable default pattern
export N8N_BLOCK_FILE_PATTERNS='^\.?/[^/]+/\.git(/.*)?$'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.