github.com
https://github.com/0xJacky/nginx-ui CVE-2026-33029
MEDIUM
Nginx UI: DoS via Negative Integer Input in Logrotate Interval
Record summary
CVE-2026-33029 has a selected CVSS score of 6.9 (medium).
Description
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enters an infinite loop or an invalid state, rendering the web interface unresponsive. This issue has been patched in version 2.3.4.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 1, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
nginx-uiBrowse 0xJacky / nginx-ui | CVE List | < 2.3.4 | affected |
github.com/0xJacky/Nginx-UIBrowse Go / github.com/0xJacky/Nginx-UI | GitHub Advisory | Through 1.99 | affected |
References
4github.com
https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4 github.comConfirmation
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-cp8r-8jvw-v3qg nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-33029