<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:06:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06993</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06993</link>
      <description>bdu:2026-06993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06993</guid>
    </item>
    <item>
      <title>EUVD-2026-278270</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278270</link>
      <description>EUVD-2026-278270</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278270</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33026</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33026</link>
      <description>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33026</guid>
    </item>
    <item>
      <title>GHSA-fhh2-gg7w-gwpq — nginx-ui Backup Restore Allows Tampering with Encrypted Backups</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fhh2-gg7w-gwpq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/Nginx-UI&lt;/p&gt;
&lt;p&gt;## Summary
The `nginx-ui` backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration.&lt;/p&gt;
&lt;p&gt;## Details
The backup format lacks a trusted integrity root. Although files are encrypted, the encryption key and IV are provided to the client and the integrity metadata (`hash_info.txt`) is encrypted using the same key. As a result, an attacker who can access the backup token can decrypt the archive, modify its contents, recompute integrity hashes, and re-encrypt the bundle.&lt;/p&gt;
&lt;p&gt;Because the restore process does not enforce integrity verification and accepts backups even when hash mismatches are detected, the system restores attacker-controlled configuration even when integrity verification warnings are raised. In certain configurations this may lead to arbitrary command execution on the host.&lt;/p&gt;
&lt;p&gt;The backup system is built around the following workflow:&lt;/p&gt;
&lt;p&gt;1. Backup files are compressed into `nginx-ui.zip` and `nginx.zip`.
2. The files are encrypted using AES-256-CBC.
3. SHA-256 hashes of the encrypted files are stored in `hash_info.txt`.
4. The hash file is also encrypted with the same AES key and IV.
5. The AES key and IV are provided to the client as a &amp;#34;backup security token&amp;#34;.&lt;/p&gt;
&lt;p&gt;This architecture creates a circular trust model:&lt;/p&gt;
&lt;p&gt;- The encryption key is available to the client.
- The integrity metadata is encrypted with that same key.
- The restore process trusts hashes contained within the backup itself.&lt;/p&gt;
&lt;p&gt;Because the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/Nginx-UI&lt;/p&gt;
&lt;p&gt;## Summary
The `nginx-ui` backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration.&lt;/p&gt;
&lt;p&gt;## Details
The backup format lacks a trusted integrity root. Although files are encrypted, the encryption key and IV are provided to the client and the integrity metadata (`hash_info.txt`) is encrypted using the same key. As a result, an attacker who can access the backup token can decrypt the archive, modify its contents, recompute integrity hashes, and re-encrypt the bundle.&lt;/p&gt;
&lt;p&gt;Because the restore process does not enforce integrity verification and accepts backups even when hash mismatches are detected, the system restores attacker-controlled configuration even when integrity verification warnings are raised. In certain configurations this may lead to arbitrary command execution on the host.&lt;/p&gt;
&lt;p&gt;The backup system is built around the following workflow:&lt;/p&gt;
&lt;p&gt;1. Backup files are compressed into `nginx-ui.zip` and `nginx.zip`.
2. The files are encrypted using AES-256-CBC.
3. SHA-256 hashes of the encrypted files are stored in `hash_info.txt`.
4. The hash file is also encrypted with the same AES key and IV.
5. The AES key and IV are provided to the client as a &amp;#34;backup security token&amp;#34;.&lt;/p&gt;
&lt;p&gt;This architecture creates a circular trust model:&lt;/p&gt;
&lt;p&gt;- The encryption key is available to the client.
- The integrity metadata is encrypted with that same key.
- The restore process trusts hashes contained within the backup itself.&lt;/p&gt;
&lt;p&gt;Because the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fhh2-gg7w-gwpq</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0931 — nginx-ui: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0931</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um sich Administratorrechte zu verschaffen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um sich Administratorrechte zu verschaffen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0931</guid>
    </item>
  </channel>
</rss>
