Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-44015
  • github.com/0xjacky/nginx-ui
Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Services 12 May
  • No fix available
  • Severity - 8.5 (High)
CVE-2026-42238
  • github.com/0xjacky/nginx-ui
Unauthenticated Remote Code Execution via Backup Restore in nginx-ui 04 May
  • Fix available
  • Severity - 9.0 (Critical)
CVE-2026-42223
  • github.com/0xjacky/nginx-ui
nginx-ui: Settings API Exposes Protected Secrets 04 May
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-42222
  • github.com/0xjacky/nginx-ui
nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover 04 May
  • No fix available
  • Severity - 8.1 (High)
CVE-2026-42221
  • github.com/0xjacky/nginx-ui
nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim 04 May
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-42220
  • github.com/0xjacky/nginx-ui
nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback 04 May
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-34403
  • github.com/0xjacky/nginx-ui
Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints 20 Apr
  • Fix available
  • Severity - 5.5 (Medium)
CVE-2026-33031
  • github.com/0xjacky/nginx-ui
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens 20 Apr
  • Fix available
  • Severity - 8.6 (High)
CVE-2026-33026
  • github.com/0xjacky/nginx-ui
nginx-ui Backup Restore Allows Tampering with Encrypted Backups 30 Mar
  • Fix available
  • Severity - 9.4 (Critical)
CVE-2026-33027
  • github.com/0xjacky/nginx-ui
Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory 30 Mar
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-33028
  • github.com/0xjacky/nginx-ui
  • github.com/uozi-tech/cosy
Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse 30 Mar
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-33029
  • github.com/0xjacky/nginx-ui
Nginx UI: DoS via Negative Integer Input in Logrotate Interval 30 Mar
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-33030
  • github.com/0xjacky/nginx-ui
Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys 30 Mar
  • No fix available
  • Severity - 8.8 (High)
CVE-2026-33032
  • github.com/0xjacky/nginx-ui
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover 30 Mar
  • No fix available
  • Severity - 9.8 (Critical)
CVE-2026-27944
  • github.com/0xjacky/nginx-ui
Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure 05 Mar
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2024-49368
  • github.com/0xjacky/nginx-ui
Unchecked logrotate settings lead to arbitrary command execution 21 Oct 2024
  • Fix available
  • Severity - 8.9 (High)