blob: a463a6d9229d57748394c7ae0deba90a8e468de1 [file]
id: GO-2026-4904
modules:
- module: github.com/0xJacky/Nginx-UI
unsupported_versions:
- last_affected: 1.99.0
vulnerable_at: 1.9.9
summary: nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI
cves:
- CVE-2026-33032
ghsas:
- GHSA-h6c2-x2m2-mwhf
references:
- advisory: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-33032
- web: https://github.com/0xJacky/nginx-ui/blob/f89f8ff8223478988f7ed49bf1d3dbf2de44bf92/internal/middleware/ip_whitelist.go#L11-L26
- web: https://github.com/0xJacky/nginx-ui/blob/f89f8ff8223478988f7ed49bf1d3dbf2de44bf92/mcp/router.go#L9-L17
source:
id: GHSA-h6c2-x2m2-mwhf
created: 2026-03-31T13:04:30.980558-04:00
review_status: UNREVIEWED