PT-2026-29090 · Nginx-Ui · Nginx-Ui

·

CVE-2026-33029

·

Published

2026-03-30

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nginx UI versions prior to 2.3.4
Description An input validation issue in the logrotate configuration allows an authenticated user to cause a Denial of Service (DoS). Submitting a negative integer for the rotation interval causes the backend to enter an infinite loop or an invalid state, making the web interface unresponsive. The issue resides in the handler for the API Endpoint /api/settings, specifically within the logrotate.interval Vulnerable Parameter. When a negative value is processed, it triggers a non-terminating loop, consuming CPU resources and preventing the server from handling further requests.
Recommendations Versions prior to 2.3.4 should be updated to version 2.3.4 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04701
CVE-2026-33029
GHSA-CP8R-8JVW-V3QG
GO-2026-4902
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1205-1

Affected Products

Nginx-Ui