<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:07:58.760462+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06993</id>
    <title>bdu:2026-06993</title>
    <updated>2026-10-04T01:07:58.874401+00:00</updated>
    <content>bdu:2026-06993</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278270</id>
    <title>EUVD-2026-278270</title>
    <updated>2026-10-04T01:07:58.874444+00:00</updated>
    <content>EUVD-2026-278270</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278270"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33026</id>
    <title>fkie_cve-2026-33026</title>
    <updated>2026-10-04T01:07:58.874458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33026"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fhh2-gg7w-gwpq</id>
    <title>GHSA-fhh2-gg7w-gwpq — nginx-ui Backup Restore Allows Tampering with Encrypted Backups</title>
    <updated>2026-10-04T01:07:58.874489+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/0xJacky/Nginx-UI</p>
<p>## Summary
The `nginx-ui` backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration.</p>
<p>## Details
The backup format lacks a trusted integrity root. Although files are encrypted, the encryption key and IV are provided to the client and the integrity metadata (`hash_info.txt`) is encrypted using the same key. As a result, an attacker who can access the backup token can decrypt the archive, modify its contents, recompute integrity hashes, and re-encrypt the bundle.</p>
<p>Because the restore process does not enforce integrity verification and accepts backups even when hash mismatches are detected, the system restores attacker-controlled configuration even when integrity verification warnings are raised. In certain configurations this may lead to arbitrary command execution on the host.</p>
<p>The backup system is built around the following workflow:</p>
<p>1. Backup files are compressed into `nginx-ui.zip` and `nginx.zip`.
2. The files are encrypted using AES-256-CBC.
3. SHA-256 hashes of the encrypted files are stored in `hash_info.txt`.
4. The hash file is also encrypted with the same AES key and IV.
5. The AES key and IV are provided to the client as a "backup security token".</p>
<p>This architecture creates a circular trust model:</p>
<p>- The encryption key is available to the client.
- The integrity metadata is encrypted with that same key.
- The restore process trusts hashes contained within the backup itself.</p>
<p>Because the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fhh2-gg7w-gwpq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0931</id>
    <title>WID-SEC-W-2026-0931 — nginx-ui: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:07:58.874562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um sich Administratorrechte zu verschaffen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0931"/>
  </entry>
</feed>
