PT-2026-29090 · Nginx-Ui · Nginx-Ui
Dapickle
·
Publicado
2026-03-30
·
Atualizado
2026-04-07
·
CVE-2026-33029
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nginx UI versions prior to 2.3.4
Description
An input validation issue in the logrotate configuration allows an authenticated user to cause a Denial of Service (DoS). Submitting a negative integer for the rotation interval causes the backend to enter an infinite loop or an invalid state, making the web interface unresponsive. The issue resides in the handler for the API Endpoint
/api/settings, specifically within the logrotate.interval Vulnerable Parameter. When a negative value is processed, it triggers a non-terminating loop, consuming CPU resources and preventing the server from handling further requests.Recommendations
Versions prior to 2.3.4 should be updated to version 2.3.4 or later.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nginx-Ui