Security: 0xJacky/nginx-ui
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
External notification test requests lacked interactive secure-session enforcementGHSA-49r7-63h8-8p86 published
Aug 12, 2026 by 0xJackyModerate -
Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIsGHSA-33rr-wq23-g6gg published
Aug 12, 2026 by 0xJackyHigh -
Incomplete fix of GHSA-5v7c-xpfp-p65m - the api/cluster router (node CRUD, cluster-wide reload/restartGHSA-h246-wpgf-vmq5 published
Aug 12, 2026 by 0xJackyHigh -
0xJacky/nginx-ui Backup Restore ZIP Symlink Handling Can Pollute Nginx Configuration DirectoryGHSA-qfwj-23j7-6939 published
Aug 12, 2026 by 0xJackyLow -
Static node secret grants full unauthenticated admin (user creation + terminal RCE) — still present in 2.4.2GHSA-w8p3-r29g-jg3p published
Jul 29, 2026 by 0xJackyHigh -
0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUserGHSA-32gc-wf3m-78w9 published
Aug 12, 2026 by 0xJackyHigh -
Self-upgrade runs an unsigned binary verified only by a same-origin digest (CWE-494) → RCE via a compromised mirror or MITMGHSA-662p-52hx-cmh2 published
Aug 12, 2026 by 0xJackyHigh -
nginx config directive denylist (ValidateConfigFile) is bypassable via same-line ";" separation → authenticated directive injection (RCE on the official image)GHSA-cf23-7qxj-xmhr published
Jul 17, 2026 by 0xJackyHigh -
MCP nginx_config_add skips config directive validation → authenticated nginx directive injection (RCE on the official image)GHSA-76pm-mq2q-9gcr published
Jul 17, 2026 by 0xJackyHigh -
Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)GHSA-45gv-9wjv-xh7p published
Aug 12, 2026 by 0xJackyHigh