<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 18:00:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04700</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04700</link>
      <description>bdu:2026-04700</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04700</guid>
    </item>
    <item>
      <title>EUVD-2026-278180</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278180</link>
      <description>EUVD-2026-278180</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278180</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33027</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33027</link>
      <description>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire /etc/nginx directory, resulting in a partial Denial of Service. This issue has been patched in version 2.3.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire /etc/nginx directory, resulting in a partial Denial of Service. This issue has been patched in version 2.3.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33027</guid>
    </item>
    <item>
      <title>GHSA-m8p8-53vf-8357 — Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m8p8-53vf-8357</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/Nginx-UI&lt;/p&gt;
&lt;p&gt;## Summary
The nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire `/etc/nginx` directory, resulting in a partial Denial of Service.&lt;/p&gt;
&lt;p&gt;## Details
The file deletion logic fails to correctly validate and normalize paths containing URL-encoded traversal sequences such as `..%252F`.&lt;/p&gt;
&lt;p&gt;When such input is processed, the internal path resolution logic attempts to clamp the path into the allowed configuration directory. Instead of rejecting the traversal attempt, the clamping mechanism resolves the path to the base Nginx configuration directory itself.&lt;/p&gt;
&lt;p&gt;Because the deletion handler invokes `os.RemoveAll`, which recursively removes directories, this results in the deletion of the entire `/etc/nginx` directory.&lt;/p&gt;
&lt;p&gt;This behavior creates a dangerous interaction between path normalization and deletion logic:&lt;/p&gt;
&lt;p&gt;- Traversal sequences are not rejected.
- Double-encoding (`..%252F`) is used to bypass initial shallow filters.
- The clamping mechanism resolves malicious paths to the base configuration directory.
- The deletion handler recursively deletes the resolved path.&lt;/p&gt;
&lt;p&gt;As a result, an attacker can trigger deletion of the entire Nginx configuration directory instead of being blocked by path validation logic.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The vul…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/Nginx-UI&lt;/p&gt;
&lt;p&gt;## Summary
The nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire `/etc/nginx` directory, resulting in a partial Denial of Service.&lt;/p&gt;
&lt;p&gt;## Details
The file deletion logic fails to correctly validate and normalize paths containing URL-encoded traversal sequences such as `..%252F`.&lt;/p&gt;
&lt;p&gt;When such input is processed, the internal path resolution logic attempts to clamp the path into the allowed configuration directory. Instead of rejecting the traversal attempt, the clamping mechanism resolves the path to the base Nginx configuration directory itself.&lt;/p&gt;
&lt;p&gt;Because the deletion handler invokes `os.RemoveAll`, which recursively removes directories, this results in the deletion of the entire `/etc/nginx` directory.&lt;/p&gt;
&lt;p&gt;This behavior creates a dangerous interaction between path normalization and deletion logic:&lt;/p&gt;
&lt;p&gt;- Traversal sequences are not rejected.
- Double-encoding (`..%252F`) is used to bypass initial shallow filters.
- The clamping mechanism resolves malicious paths to the base configuration directory.
- The deletion handler recursively deletes the resolved path.&lt;/p&gt;
&lt;p&gt;As a result, an attacker can trigger deletion of the entire Nginx configuration directory instead of being blocked by path validation logic.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The vul…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m8p8-53vf-8357</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0931 — nginx-ui: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0931</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um sich Administratorrechte zu verschaffen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um sich Administratorrechte zu verschaffen, beliebigen Code auszuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0931</guid>
    </item>
  </channel>
</rss>
