CVE-2026-61630
nginx ignition has TOTP Reuse During Validity Window
CVSS Score
4.2
EPSS Score
0.0%
EPSS Percentile
0th
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
| CWE | CWE-287 |
| Vendor | lucasdillmann |
| Product | nginx-ignition |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for lucasdillmann nginx-ignition
Be the first to know when new medium vulnerabilities affecting lucasdillmann nginx-ignition are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
lucasdillmann / nginx-ignition
>= 2.33.0, < 2.35.1
References
github.com: https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f github.com: https://github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e github.com: https://github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107