PT-2026-29090 · Nginx-Ui · Nginx-Ui

Dapickle

·

Publicado

2026-03-30

·

Atualizado

2026-04-07

·

CVE-2026-33029

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nginx UI versions prior to 2.3.4
Description An input validation issue in the logrotate configuration allows an authenticated user to cause a Denial of Service (DoS). Submitting a negative integer for the rotation interval causes the backend to enter an infinite loop or an invalid state, making the web interface unresponsive. The issue resides in the handler for the API Endpoint /api/settings, specifically within the logrotate.interval Vulnerable Parameter. When a negative value is processed, it triggers a non-terminating loop, consuming CPU resources and preventing the server from handling further requests.
Recommendations Versions prior to 2.3.4 should be updated to version 2.3.4 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04701
CVE-2026-33029
GHSA-CP8R-8JVW-V3QG
GO-2026-4902
SUSE-SU-2026:1205-1

Produtos afetados

Nginx-Ui