CVE-2026-44015
- EPSS 0.32%
- Veröffentlicht 12.05.2026 20:49:16
- Zuletzt bearbeitet 14.05.2026 22:16:43
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with ...
CVE-2026-42238
- EPSS 0.76%
- Veröffentlicht 04.05.2026 20:13:22
- Zuletzt bearbeitet 06.05.2026 14:45:44
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh instal...
CVE-2026-42223
- EPSS 0.3%
- Veröffentlicht 04.05.2026 20:12:00
- Zuletzt bearbeitet 06.05.2026 14:46:24
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are...
CVE-2026-42222
- EPSS 0.34%
- Veröffentlicht 04.05.2026 20:11:11
- Zuletzt bearbeitet 06.05.2026 17:47:59
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are av...
CVE-2026-42221
- EPSS 0.35%
- Veröffentlicht 04.05.2026 20:09:37
- Zuletzt bearbeitet 06.05.2026 17:17:57
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The...
CVE-2026-42220
- EPSS 0.3%
- Veröffentlicht 04.05.2026 20:08:07
- Zuletzt bearbeitet 06.05.2026 17:16:36
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by AuthRequired()...
CVE-2026-34403
- EPSS 0.18%
- Veröffentlicht 20.04.2026 20:16:47
- Zuletzt bearbeitet 22.04.2026 17:35:42
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijacking (CSWSH). ...
CVE-2026-33031
- EPSS 0.27%
- Veröffentlicht 20.04.2026 20:12:07
- Zuletzt bearbeitet 22.04.2026 17:33:03
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not ac...
CVE-2026-33026
- EPSS 0.33%
- Veröffentlicht 30.03.2026 19:26:27
- Zuletzt bearbeitet 01.04.2026 18:16:43
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has b...
CVE-2026-33027
- EPSS 0.4%
- Veröffentlicht 30.03.2026 17:59:30
- Zuletzt bearbeitet 01.04.2026 18:33:36
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx c...