GO-2026-5210

Source
https://pkg.go.dev/vuln/GO-2026-5210
Import Source
https://vuln.go.dev/ID/GO-2026-5210.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2026-5210
Aliases
Published
2026-06-25T18:43:15Z
Modified
2026-06-25T19:45:14.020072500Z
Summary
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI
Details

Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI

Database specific
{
    "review_status": "UNREVIEWED",
    "url": "https://pkg.go.dev/vuln/GO-2026-5210"
}
References

Affected packages

Go / github.com/0xJacky/Nginx-UI

Package

Name
github.com/0xJacky/Nginx-UI
View open source insights on deps.dev
Purl
pkg:golang/github.com/0xJacky/Nginx-UI

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.10-0.20260316053337-1a9cd29a3082

Database specific

source
"https://vuln.go.dev/ID/GO-2026-5210.json"