| id: GO-2026-4904 |
| modules: |
| - module: github.com/0xJacky/Nginx-UI |
| unsupported_versions: |
| - last_affected: 1.99.0 |
| vulnerable_at: 1.9.9 |
| summary: nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI |
| cves: |
| - CVE-2026-33032 |
| ghsas: |
| - GHSA-h6c2-x2m2-mwhf |
| references: |
| - advisory: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-33032 |
| - web: https://github.com/0xJacky/nginx-ui/blob/f89f8ff8223478988f7ed49bf1d3dbf2de44bf92/internal/middleware/ip_whitelist.go#L11-L26 |
| - web: https://github.com/0xJacky/nginx-ui/blob/f89f8ff8223478988f7ed49bf1d3dbf2de44bf92/mcp/router.go#L9-L17 |
| source: |
| id: GHSA-h6c2-x2m2-mwhf |
| created: 2026-03-31T13:04:30.980558-04:00 |
| review_status: UNREVIEWED |