๐Ÿ” CVE Alert

CVE-2026-61630

MEDIUM 4.2

nginx ignition has TOTP Reuse During Validity Window

CVSS Score
4.2
EPSS Score
0.0%
EPSS Percentile
0th

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.

CWE CWE-287
Vendor lucasdillmann
Product nginx-ignition
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for lucasdillmann nginx-ignition

Be the first to know when new medium vulnerabilities affecting lucasdillmann nginx-ignition are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

lucasdillmann / nginx-ignition
>= 2.33.0, < 2.35.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f github.com: https://github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e github.com: https://github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107