github.com/0xJacky/Nginx-UI
Go26 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/0xJacky/Nginx-UIpage 1 of 1
- CVE-2024-22196HIGHCVSS 7.0EG 7.0fixed in 1.9.10-0.20231219195202-ec93ab05a3ec2024-01-11
Nginx-UI is an online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"` and `"id"` values…
- CVE-2024-22197HIGHCVSS 7.7EG 7.7fixed in 1.9.10-0.20231219184941-827e76c46e632024-01-11
Nginx-ui is online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `…
- CVE-2024-22198HIGHCVSS 7.1EG 7.1fixed in 1.9.10-0.20231219184941-827e76c46e632024-01-11
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secr…
- CVE-2024-23827CRITICALCVSS 9.8EG 9.8fixed in 1.9.10-0.20240128060047-8581bdd3c6f42024-01-29
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitr…
- CVE-2024-23828HIGHCVSS 8.8EG 8.8fixed in 1.9.10-0.20240126104956-d70e37c8575e2024-01-29
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incom…
- CVE-2026-107804MEDIUMCVSS 5.3EG 5.3fixed in 1.9.10-0.20260904075558-e30e331303fc2026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requ…
- CVE-2026-107805HIGHCVSS 7.5EG 7.5fixed in 1.9.10-0.20260901043436-8c9b9a1aff212026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body…
- CVE-2026-107806CRITICALCVSS 9.4EG 9.4fixed in 1.9.10-0.20260728074146-a467ed6525912026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /ap…
- CVE-2026-107807HIGHCVSS 8.8EG 8.8fixed in 1.9.10-0.20260728074433-a3999bd78a3b2026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring t…
- CVE-2026-107808HIGHCVSS 8.1EG 8.1fixed in 1.9.10-0.20260728074558-95cd21b708142026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only acc…
- CVE-2026-107809HIGHCVSS 8.8EG 8.8fixed in 1.9.10-0.20260728074433-a3999bd78a3b2026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do …
- CVE-2026-107810HIGHCVSS 8.1EG 8.1fixed in 1.9.10-0.20260728074146-a467ed6525912026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Ngin…
- CVE-2026-107811HIGHCVSS 8.8EG 8.8fixed in 1.9.10-0.20260728091109-0ecbd106c37b2026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-…
- CVE-2026-107812HIGHCVSS 7.5EG 7.5fixed in 1.9.10-0.20260728114330-580585516dd82026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or netwo…
- CVE-2026-107813HIGHCVSS 8.8EG 8.8fixed in 1.9.10-0.20260728074433-a3999bd78a3b2026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without Requ…
- CVE-2026-27944CRITICALCVSS 9.8EG 9.8fixed in 2.3.32026-03-05
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security resp…
- CVE-2026-33026CRITICALCVSS 9.1EG 9.1fixed in 1.9.10-0.20260315015203-f61bcec547c02026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This …
- CVE-2026-33027MEDIUMCVSS 6.5EG 6.52026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the b…
- CVE-2026-33028HIGHCVSS 7.5EG 7.52026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, co…
- CVE-2026-33029MEDIUMCVSS 6.5EG 6.52026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a n…
- CVE-2026-33031HIGHCVSS 8.1EG 8.1fixed in 1.9.10-0.20260314152518-7b66578adb472026-04-20
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account …
- CVE-2026-33032CRITICALCVSS 9.8EG 9.82026-03-30
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and a…
- CVE-2026-34403HIGHCVSS 8.1EG 8.1fixed in 1.9.10-0.20260316053337-1a9cd29a30822026-04-20
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijackin…
- CVE-2026-42220MEDIUMCVSS 6.5EG 6.52026-05-04
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by Aut…
- CVE-2026-42221HIGHCVSS 8.1EG 8.1fixed in 2.3.82026-05-04
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup …
- CVE-2026-44015HIGHCVSS 8.5EG 8.52026-05-12
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API req…
Check whether github.com/0xJacky/Nginx-UI is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/0xJacky/Nginx-UI CVEs against the assets you own.
Book a Demo →