๐Ÿ” CVE Alert

CVE-2026-33029

MEDIUM 6.5

Nginx UI: DoS via Negative Integer Input in Logrotate Interval

CVSS Score
6.5
EPSS Score
0.1%
EPSS Percentile
18th

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enters an infinite loop or an invalid state, rendering the web interface unresponsive. This issue has been patched in version 2.3.4.

CWE CWE-20
Vendor 0xjacky
Product nginx-ui
Published Mar 30, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for 0xjacky nginx-ui

Be the first to know when new medium vulnerabilities affecting 0xjacky nginx-ui are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

0xJacky / nginx-ui
< 2.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-cp8r-8jvw-v3qg github.com: https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4