github.com/lucasdillmann/nginx-ignition
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/lucasdillmann/nginx-ignitionpage 1 of 1
- CVE-2026-61628HIGHCVSS 8.1EG 8.1✓ Fixed in 0.0.0-20260621194639-0586b4e55ab2026-09-21
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the ha…
- CVE-2026-61629HIGHCVSS 7.5EG 7.5✓ Fixed in 0.0.0-20260526022344-0c988fc1277c2026-09-21
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLan…
- CVE-2026-61630MEDIUMCVSS 4.2EG 4.2✓ Fixed in 0.0.0-20260328015550-8d35e1eb5dd62026-09-21
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issu…
Check whether github.com/lucasdillmann/nginx-ignition is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/lucasdillmann/nginx-ignition CVEs against the assets you own.
Book a Demo →