Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/0xjacky/nginx-ui

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypassing network segmentation and enabling access to services bound to localhost or internal networks.

Join the discussion

CVE-2026-42238 is a critical code injection vulnerability in 0xJacky's nginx-ui prior to version 2.3.8. The vulnerability arises because the backup restore endpoint is unauthenticated for the first 10 minutes after startup on fresh installations. An attacker can exploit this by uploading a crafted backup archive that overwrites configuration files, allowing arbitrary OS command injection via the TestConfigCmd setting. This command executes with the privileges of the nginx-ui process user, often root in Docker deployments. The issue is patched in version 2.3.8.

Join the discussion

CVE-2026-42223 is a vulnerability in 0xJacky's nginx-ui prior to version 2.3.8 where the GetSettings API handler exposes over 40 sensitive configuration fields to authenticated users. These fields include JwtSecret, NodeSecret, OIDC ClientSecret, and IP whitelist configurations. The issue arises because the protection tag on sensitive fields is enforced only during writes but ignored during reads, leading to unintended disclosure of sensitive information. This vulnerability has been patched in version 2.3.8. The CVSS score is 6.5, indicating a medium severity level.

Join the discussion

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.

Join the discussion

CVE-2026-42221 is a high-severity vulnerability in 0xJacky's nginx-ui versions 2.0.0 up to but not including 2.3.8. It allows an unauthenticated remote attacker to claim the initial administrator account during the first-run setup by accessing the public /api/install endpoint without authentication. This leads to permanent takeover of the initial instance by setting the admin email, username, and password. The vulnerability arises because the installation endpoint lacks authentication, and encryption only protects data in transit, not the authorization of the installer. This issue has been fixed in version 2.3.

Join the discussion

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by AuthRequired() through the X-Node-Secret header (or node_secret query parameter), causing the request to be treated as authenticated via the trusted-node path and associated with the init user. This issue has been patched in version 2.3.8.

Join the discussion

CVE-2026-34403 is a medium severity vulnerability in 0xJacky's nginx-ui prior to version 2.3.5. The issue arises because all WebSocket endpoints use a gorilla/websocket Upgrader with CheckOrigin always returning true, which allows Cross-Site WebSocket Hijacking (CSWSH). Since authentication tokens are stored in browser cookies without HttpOnly or SameSite attributes, a malicious webpage can establish authenticated WebSocket connections if an administrator visits it. Version 2.3.5 addresses this vulnerability.

Join the discussion

CVE-2026-33031 is an improper access control vulnerability in 0xJacky's nginx-ui versions prior to 2.3.4. The issue allows users who have been disabled by an administrator to continue using previously issued API tokens until those tokens expire. This means that disabling a compromised account does not immediately revoke access, enabling an attacker with a stolen JWT to keep reading and modifying protected resources. Additionally, since tokens can be used to create new accounts, the disabled user may maintain privileges indefinitely. Version 2.3.4 addresses this vulnerability.

Join the discussion

CVE-2026-33026 is a critical vulnerability in the 0xJacky nginx-ui web user interface for the Nginx web server. Versions prior to 2.3.4 have a flaw in the backup restore mechanism that allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue involves cleartext storage of sensitive information and improper validation of backup archives. The vulnerability has been patched in version 2.3.4. The CVSS 4.0 score is 9.4, indicating a critical severity level.

Join the discussion

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire /etc/nginx directory, resulting in a partial Denial of Service. This issue has been patched in version 2.3.4.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Package: pkg:github/0xjacky/nginx-ui
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses