PT-2026-29090 · Nginx-Ui · Nginx-Ui

Dapickle

·

Published

2026-03-30

·

Updated

2026-04-07

·

CVE-2026-33029

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nginx UI versions prior to 2.3.4
Description An input validation issue in the logrotate configuration allows an authenticated user to cause a Denial of Service (DoS). Submitting a negative integer for the rotation interval causes the backend to enter an infinite loop or an invalid state, making the web interface unresponsive. The issue resides in the handler for the API Endpoint /api/settings, specifically within the logrotate.interval Vulnerable Parameter. When a negative value is processed, it triggers a non-terminating loop, consuming CPU resources and preventing the server from handling further requests.
Recommendations Versions prior to 2.3.4 should be updated to version 2.3.4 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-04701
CVE-2026-33029
GHSA-CP8R-8JVW-V3QG
GO-2026-4902
SUSE-SU-2026:1205-1

Affected Products

Nginx-Ui