Количество 3
Количество 3
CVE-2026-33027
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire /etc/nginx directory, resulting in a partial Denial of Service. This issue has been patched in version 2.3.4.
GHSA-m8p8-53vf-8357
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation
BDU:2026-04700
Уязвимость пользовательского интерфейса Nginx UI сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33027 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire /etc/nginx directory, resulting in a partial Denial of Service. This issue has been patched in version 2.3.4. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-m8p8-53vf-8357 Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation | 0% Низкий | 5 месяцев назад | ||
BDU:2026-04700 Уязвимость пользовательского интерфейса Nginx UI сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 4.9 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу