<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:16:54.718238+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-02720</id>
    <title>bdu:2026-02720</title>
    <updated>2026-10-03T15:16:54.792145+00:00</updated>
    <content>bdu:2026-02720</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-02720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276567</id>
    <title>EUVD-2026-276567</title>
    <updated>2026-10-03T15:16:54.792186+00:00</updated>
    <content>EUVD-2026-276567</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27944</id>
    <title>fkie_cve-2026-27944</title>
    <updated>2026-10-03T15:16:54.792201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g9w5-qffc-6762</id>
    <title>GHSA-g9w5-qffc-6762 — Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure</title>
    <updated>2026-10-03T15:16:54.792234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/0xJacky/Nginx-UI</p>
<p>## Summary</p>
<p>The `/api/backup` endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the `X-Backup-Security` response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately.</p>
<p>## Vulnerability Details</p>
<p>| Field | Value |
|-------|-------|
| CWE | CWE-306: Missing Authentication for Critical Function + CWE-311: Missing Encryption of Sensitive Data |
| Affected File | `api/backup/router.go` |
| Affected Function | `CreateBackup` (lines 8-11 in router, implementation in `api/backup/backup.go:13-38`) |
| Secondary File | `internal/backup/backup.go` |
| CVSS 3.1 | 9.8 (Critical) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |</p>
<p>## Root Cause</p>
<p>The vulnerability exists due to two critical security flaws:</p>
<p>### 1. Missing Authentication on /api/backup Endpoint</p>
<p>In `api/backup/router.go:9`, the backup endpoint is registered without any authentication middleware:</p>
<p>```go
func InitRouter(r *gin.RouterGroup) {
	r.GET("/backup", CreateBackup)  // No authentication required
	r.POST("/restore", middleware.EncryptedForm(), RestoreBackup)  // Has middleware
}
```</p>
<p>For comparison, the restore endpoint correctly uses middleware, while the backup endpoint is completely open.</p>
<p>### 2. Encryption Keys Disclosed in HTTP Response Headers</p>
<p>In `api/backup/backup.go:22-33`, the AES…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g9w5-qffc-6762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0712</id>
    <title>WID-SEC-W-2026-0712 — nginx-ui: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T15:16:54.792327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in nginx-ui ausnutzen, um Sicherheitsvorkehrungen zu umgehen und so eine vollständige Systembackup mit sensiblen Daten offenzulegen und zu entschlüsseln.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0712"/>
  </entry>
</feed>
