go

github.com/0xJacky/Nginx-UI

View on go registry
40 Total advisories
40 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/0xJacky/Nginx-UI is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-33028

nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse

UNKNOWN
Go

CVE-2026-33027

Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation

CRITICAL 9.8
Go

CVE-2026-33032

nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

UNKNOWN
Go

CVE-2026-33029

nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval

HIGH 8.8
Go

CVE-2026-33030

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys

MEDIUM 6.5
Go

CVE-2026-42220

Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback

UNKNOWN
Go

CVE-2026-33026

nginx-ui Backup Restore Allows Tampering with Encrypted Backups

CRITICAL 9.8
Go

CVE-2024-23827

Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature

HIGH 7.0
Go

CVE-2024-22196

Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)

HIGH 8.8
Go

CVE-2024-23828

Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF

HIGH 7.1
Go

CVE-2024-22198

Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)

HIGH 7.7
Go

CVE-2024-22197

Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)

HIGH 8.1
Go

CVE-2026-42222

Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover

HIGH 8.1
Go

CVE-2026-33031

Nginx-UI: Disabled users retain full API access through previously issued bearer tokens

MEDIUM 6.5
Go

CVE-2026-42223

Nginx-UI Settings API Exposes Protected Secrets

HIGH 8.5
Go

CVE-2026-44015

Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services

HIGH 8.1
Go

CVE-2026-42221

Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim

UNKNOWN
Go

CVE-2026-33031

Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2026-42223

Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui

UNKNOWN
Go

CVE-2026-44015

Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2026-42222

Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui

UNKNOWN
Go

CVE-2026-42221

Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI

HIGH 8.1
Go

CVE-2026-34403

Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints

UNKNOWN
Go

CVE-2026-42220

Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2026-34403

Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI

CRITICAL 9.8
Go

CVE-2026-42238

Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore

UNKNOWN
Go

CVE-2026-42238

Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui

UNKNOWN
Go

CVE-2026-33030

nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui

UNKNOWN
Go

CVE-2026-33028

nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2026-33032

nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2026-33027

Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2026-33026

nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2026-33029

nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI

CRITICAL 9.8
Go

CVE-2026-27944

Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure

UNKNOWN
Go

CVE-2026-27944

Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2024-23827

Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2024-23828

Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2024-22197

Remote command execution in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2024-22196

SQL injection in github.com/0xJacky/Nginx-UI

UNKNOWN
Go

CVE-2024-22198

Arbitrary command execution in github.com/0xJacky/Nginx-UI

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes