PT-2026-29090 · Nginx-Ui · Nginx-Ui
Dapickle
·
Published
2026-03-30
·
Updated
2026-04-07
·
CVE-2026-33029
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nginx UI versions prior to 2.3.4
Description
An input validation issue in the logrotate configuration allows an authenticated user to cause a Denial of Service (DoS). Submitting a negative integer for the rotation interval causes the backend to enter an infinite loop or an invalid state, making the web interface unresponsive. The issue resides in the handler for the API Endpoint
/api/settings, specifically within the logrotate.interval Vulnerable Parameter. When a negative value is processed, it triggers a non-terminating loop, consuming CPU resources and preventing the server from handling further requests.Recommendations
Versions prior to 2.3.4 should be updated to version 2.3.4 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx-Ui