<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:25:02.524856+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06344</id>
    <title>bdu:2026-06344</title>
    <updated>2026-10-03T19:25:02.574151+00:00</updated>
    <content>bdu:2026-06344</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06344"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308555</id>
    <title>EUVD-2026-308555</title>
    <updated>2026-10-03T19:25:02.574192+00:00</updated>
    <content>EUVD-2026-308555</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42223</id>
    <title>fkie_cve-2026-42223</title>
    <updated>2026-10-03T19:25:02.574206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:"true" - however, this tag is only enforced during writes (via ProtectedFill in SaveSettings) and is completely ignored during reads. This exposes 40+ protected fields including JwtSecret (enabling auth token forgery), NodeSecret (enabling cluster node impersonation), OIDC ClientSecret (enabling OAuth account takeover), and the IP whitelist configuration. This issue has been patched in version 2.3.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q4w7-56hr-83rm</id>
    <title>GHSA-q4w7-56hr-83rm — Nginx-UI Settings API Exposes Protected Secrets</title>
    <updated>2026-10-03T19:25:02.574242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/0xJacky/nginx-ui</p>
<p>### Summary
The `GetSettings` API handler (`api/settings/settings.go:24-65`) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with `protected:"true"` - however, this tag is only enforced during writes (via `ProtectedFill` in `SaveSettings`) and is completely ignored during reads. This exposes 40+ protected fields including `JwtSecret` (enabling auth token forgery), `NodeSecret` (enabling cluster node impersonation), OIDC `ClientSecret` (enabling OAuth account takeover), and the IP whitelist configuration.</p>
<p>### Details
#### Vulnerable Code</p>
<p>**`api/settings/settings.go:49-64` - GetSettings serializes all fields**</p>
<p>```go
c.JSON(http.StatusOK, gin.H{
    "app":       cSettings.AppSettings,
    "server":    cSettings.ServerSettings,
    "database":  settings.DatabaseSettings,
    "auth":      settings.AuthSettings,
    "casdoor":   settings.CasdoorSettings,
    "oidc":      settings.OIDCSettings,
    "cert":      settings.CertSettings,
    "http":      settings.HTTPSettings,
    "logrotate": settings.LogrotateSettings,
    "nginx":     settings.NginxSettings,
    "node":      settings.NodeSettings,
    "openai":    settings.OpenAISettings,
    "terminal":  settings.TerminalSettings,
    "webauthn":  settings.WebAuthnSettings,
})
```</p>
<p>Go's `json.Marshal` serializes all exported fields with `json:` tags. The `protected:"true"` struct tag is a custom tag - it has no effect on JSON serialization.</p>
<p>#### Protection is Wri…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q4w7-56hr-83rm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1276</id>
    <title>WID-SEC-W-2026-1276 — nginx-ui: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:25:02.574305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um beliebigen Code mit Root-Rechten auszuführen, sich Administratorrechte zu verschaffen und die vollständige Kontrolle über das System zu erlangen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1276"/>
  </entry>
</feed>
