github.com/0xjacky/nginx-ui
Activity
- Latest release
- 3y ago
- Total releases
- 53
- Cadence
- ~3 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Jan 27, 2022
| Version | Released | |
|---|---|---|
v1.9.9-4
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.9.9-4
pre
Dependencies (30)
+ 22 more |
|
v1.9.9-3
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.9.9-3
pre
Dependencies (28)
+ 20 more |
|
v1.9.9-2
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.9.9-2
pre
Dependencies (28)
+ 20 more |
|
v1.9.9
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.9.9
minor
Dependencies (28)
+ 20 more |
|
v1.9.9-1
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.9.9-1
pre
Dependencies (28)
+ 20 more |
|
v1.8.4-patch
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.8.4-patch
pre
Dependencies (28)
+ 20 more |
|
v1.8.4
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.8.4
patch
Dependencies (28)
+ 20 more |
|
v1.8.3
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.8.3
patch
Dependencies (28)
+ 20 more |
|
v1.8.2
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.8.2
patch
Dependencies (28)
+ 20 more |
|
v1.8.1
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.8.1
minor
Dependencies (28)
+ 20 more |
|
v1.8.0
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.8.0
minor
Dependencies (28)
+ 20 more |
|
v1.7.9
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.9
patch
Dependencies (27)
+ 19 more |
|
v1.7.8
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.8
patch
Dependencies (27)
+ 19 more |
|
v1.7.7
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.7
patch
Dependencies (24)
+ 16 more |
|
v1.7.6
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.6
patch
Dependencies (23)
+ 15 more |
|
v1.7.5
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.5
patch
Dependencies (23)
+ 15 more |
|
v1.7.4
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.4
patch
Dependencies (23)
+ 15 more |
|
v1.7.3
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.3
patch
Dependencies (23)
+ 15 more |
|
v1.7.2
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.2
patch
Dependencies (23)
+ 15 more |
|
v1.7.1
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.1
minor
Dependencies (22)
+ 14 more |
|
v1.7.0-patch
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.7.0-patch
pre
Dependencies (22)
+ 14 more |
|
v1.6.7
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.6.7
patch
Dependencies (21)
+ 13 more |
|
v1.6.6
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.6.6
patch
Dependencies (21)
+ 13 more |
|
v1.6.3
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.6.3
patch
Dependencies (21)
+ 13 more |
|
v1.6.2
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.6.2
patch
Dependencies (21)
+ 13 more |
|
v1.6.1
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.6.1
minor
Dependencies (21)
+ 13 more |
|
v1.6.0-fix
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.6.0-fix
pre
Dependencies (21)
+ 13 more |
|
v1.5.2
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.2
patch
Dependencies (21)
+ 13 more |
|
v1.5.0
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0
minor
Dependencies (21)
+ 13 more |
|
v1.5.0-beta9
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0-beta9
pre
Dependencies (21)
+ 13 more |
|
v1.5.0-beta7
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0-beta7
pre
Dependencies (21)
+ 13 more |
|
v1.5.0-beta5
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0-beta5
pre
Dependencies (21)
+ 13 more |
|
v1.5.0-beta4-fix
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0-beta4-fix
pre
Dependencies (21)
+ 13 more |
|
v1.5.0-beta4
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0-beta4
pre
Dependencies (21)
+ 13 more |
|
v1.5.0-beta3
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0-beta3
pre
Dependencies (21)
+ 13 more |
|
v1.5.0-beta2
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.5.0-beta2
pre
Dependencies (21)
+ 13 more |
|
v1.4.1
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.1
patch
Dependencies (19)
+ 11 more |
|
v1.4.0
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.0
minor
Dependencies (19)
+ 11 more |
|
v1.4.0-rc1
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.4.0-rc1
pre
Dependencies (19)
+ 11 more |
|
v1.3.3-rc1
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.3-rc1
pre
Dependencies (19)
+ 11 more |
|
v1.3.2
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.2
patch
Dependencies (18)
+ 10 more |
|
v1.3.1-fix
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.1-fix
pre
Dependencies (18)
+ 10 more |
|
v1.3.1
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.1
minor
Dependencies (18)
+ 10 more |
|
v1.3.0-rc1
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.3.0-rc1
pre
Dependencies (17)
+ 9 more |
|
v1.2.2
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.2
patch
Dependencies (17)
+ 9 more |
|
v1.2.1
patch
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.1
patch
Dependencies (17)
+ 9 more |
|
v1.2.0-rc.3
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.0-rc.3
pre
Dependencies (17)
+ 9 more |
|
v1.2.0
minor
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.0
minor
Dependencies (17)
+ 9 more |
|
v1.2.0-rc.2
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.0-rc.2
pre
Dependencies (17)
+ 9 more |
|
v1.2.0-rc.1
pre
20 CVEs
CVE-2026-44015
GO-2026-5719
GHSA-wr32-99hh-6f35
Jun 25, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33031
GO-2026-5733
GHSA-x234-x5vq-cc2v
Jun 25, 2026
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260314152518-7b66578adb47
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42222
GO-2026-5521
GHSA-mxqh-q9h6-v8pq
Jun 25, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42223
GO-2026-5565
GHSA-q4w7-56hr-83rm
Jun 25, 2026
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42221
GO-2026-5412
GHSA-h27v-ph7w-m9fp
Jun 25, 2026
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI from v2.0.0 before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-34403
GO-2026-5210
GHSA-78mf-482w-62qj
Jun 25, 2026
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20260316053337-1a9cd29a3082
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42220
GO-2026-5227
GHSA-7jrr-xw9c-mj39
Jun 25, 2026
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42238
GO-2026-5129
GHSA-4pvg-prr3-9cxr
Jun 25, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/nginx-ui before v2.3.8. References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33030
GO-2026-4901
GHSA-5hf2-vhj6-gj9m
Apr 02, 2026
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33032
GO-2026-4904
GHSA-h6c2-x2m2-mwhf
Apr 02, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI References
Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33029
GO-2026-4902
GHSA-cp8r-8jvw-v3qg
Apr 02, 2026
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33028
GO-2026-4906
GHSA-m468-xcm6-fxg4
Apr 02, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33027
GO-2026-4907
GHSA-m8p8-53vf-8357
Apr 02, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-33026
GO-2026-4903
GHSA-fhh2-gg7w-gwpq
Apr 02, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI References Updated Apr 02, 2026 · Source: OSV.dev
CVE-2026-27944
GO-2026-4614
GHSA-g9w5-qffc-6762
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.3.3. References
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2024-23827
GO-2024-2481
GHSA-xvq9-4vpv-227m
Jun 28, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References
Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-23828
GO-2024-2480
GHSA-qcjq-7f7v-pvc8
Jun 28, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/0xJacky/Nginx-UI before v2.0.0-beta.12. References Updated Jul 09, 2024 · Source: OSV.dev
CVE-2024-22198
GO-2024-2462
GHSA-8r25-68wm-jw35
Jan 30, 2024
Arbitrary command execution in github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22196
GO-2024-2463
GHSA-h374-mm57-879c
Jan 17, 2024
SQL injection in github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219195202-ec93ab05a3ec
References Updated May 20, 2024 · Source: OSV.dev
CVE-2024-22197
GO-2024-2464
GHSA-pxmr-q2x3-9x9m
Jan 17, 2024
Remote command execution in github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Fixed in
1.9.10-0.20231219184941-827e76c46e63
References Updated May 20, 2024 · Source: OSV.dev |
v1.2.0-rc.1
pre
Dependencies (18)
+ 10 more |