<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:15:21 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06344</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06344</link>
      <description>bdu:2026-06344</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06344</guid>
    </item>
    <item>
      <title>EUVD-2026-308555</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308555</link>
      <description>EUVD-2026-308555</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308555</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42223</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42223</link>
      <description>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:&amp;#34;true&amp;#34; - however, this tag is only enforced during writes (via ProtectedFill in SaveSettings) and is completely ignored during reads. This exposes 40+ protected fields including JwtSecret (enabling auth token forgery), NodeSecret (enabling cluster node impersonation), OIDC ClientSecret (enabling OAuth account takeover), and the IP whitelist configuration. This issue has been patched in version 2.3.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:&amp;#34;true&amp;#34; - however, this tag is only enforced during writes (via ProtectedFill in SaveSettings) and is completely ignored during reads. This exposes 40+ protected fields including JwtSecret (enabling auth token forgery), NodeSecret (enabling cluster node impersonation), OIDC ClientSecret (enabling OAuth account takeover), and the IP whitelist configuration. This issue has been patched in version 2.3.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42223</guid>
    </item>
    <item>
      <title>GHSA-q4w7-56hr-83rm — Nginx-UI Settings API Exposes Protected Secrets</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q4w7-56hr-83rm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/nginx-ui&lt;/p&gt;
&lt;p&gt;### Summary
The `GetSettings` API handler (`api/settings/settings.go:24-65`) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with `protected:&amp;#34;true&amp;#34;` - however, this tag is only enforced during writes (via `ProtectedFill` in `SaveSettings`) and is completely ignored during reads. This exposes 40+ protected fields including `JwtSecret` (enabling auth token forgery), `NodeSecret` (enabling cluster node impersonation), OIDC `ClientSecret` (enabling OAuth account takeover), and the IP whitelist configuration.&lt;/p&gt;
&lt;p&gt;### Details
#### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`api/settings/settings.go:49-64` - GetSettings serializes all fields**&lt;/p&gt;
&lt;p&gt;```go
c.JSON(http.StatusOK, gin.H{
    &amp;#34;app&amp;#34;:       cSettings.AppSettings,
    &amp;#34;server&amp;#34;:    cSettings.ServerSettings,
    &amp;#34;database&amp;#34;:  settings.DatabaseSettings,
    &amp;#34;auth&amp;#34;:      settings.AuthSettings,
    &amp;#34;casdoor&amp;#34;:   settings.CasdoorSettings,
    &amp;#34;oidc&amp;#34;:      settings.OIDCSettings,
    &amp;#34;cert&amp;#34;:      settings.CertSettings,
    &amp;#34;http&amp;#34;:      settings.HTTPSettings,
    &amp;#34;logrotate&amp;#34;: settings.LogrotateSettings,
    &amp;#34;nginx&amp;#34;:     settings.NginxSettings,
    &amp;#34;node&amp;#34;:      settings.NodeSettings,
    &amp;#34;openai&amp;#34;:    settings.OpenAISettings,
    &amp;#34;terminal&amp;#34;:  settings.TerminalSettings,
    &amp;#34;webauthn&amp;#34;:  settings.WebAuthnSettings,
})
```&lt;/p&gt;
&lt;p&gt;Go&amp;#39;s `json.Marshal` serializes all exported fields with `json:` tags. The `protected:&amp;#34;true&amp;#34;` struct tag is a custom tag - it has no effect on JSON serialization.&lt;/p&gt;
&lt;p&gt;#### Protection is Wri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/0xJacky/nginx-ui&lt;/p&gt;
&lt;p&gt;### Summary
The `GetSettings` API handler (`api/settings/settings.go:24-65`) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with `protected:&amp;#34;true&amp;#34;` - however, this tag is only enforced during writes (via `ProtectedFill` in `SaveSettings`) and is completely ignored during reads. This exposes 40+ protected fields including `JwtSecret` (enabling auth token forgery), `NodeSecret` (enabling cluster node impersonation), OIDC `ClientSecret` (enabling OAuth account takeover), and the IP whitelist configuration.&lt;/p&gt;
&lt;p&gt;### Details
#### Vulnerable Code&lt;/p&gt;
&lt;p&gt;**`api/settings/settings.go:49-64` - GetSettings serializes all fields**&lt;/p&gt;
&lt;p&gt;```go
c.JSON(http.StatusOK, gin.H{
    &amp;#34;app&amp;#34;:       cSettings.AppSettings,
    &amp;#34;server&amp;#34;:    cSettings.ServerSettings,
    &amp;#34;database&amp;#34;:  settings.DatabaseSettings,
    &amp;#34;auth&amp;#34;:      settings.AuthSettings,
    &amp;#34;casdoor&amp;#34;:   settings.CasdoorSettings,
    &amp;#34;oidc&amp;#34;:      settings.OIDCSettings,
    &amp;#34;cert&amp;#34;:      settings.CertSettings,
    &amp;#34;http&amp;#34;:      settings.HTTPSettings,
    &amp;#34;logrotate&amp;#34;: settings.LogrotateSettings,
    &amp;#34;nginx&amp;#34;:     settings.NginxSettings,
    &amp;#34;node&amp;#34;:      settings.NodeSettings,
    &amp;#34;openai&amp;#34;:    settings.OpenAISettings,
    &amp;#34;terminal&amp;#34;:  settings.TerminalSettings,
    &amp;#34;webauthn&amp;#34;:  settings.WebAuthnSettings,
})
```&lt;/p&gt;
&lt;p&gt;Go&amp;#39;s `json.Marshal` serializes all exported fields with `json:` tags. The `protected:&amp;#34;true&amp;#34;` struct tag is a custom tag - it has no effect on JSON serialization.&lt;/p&gt;
&lt;p&gt;#### Protection is Wri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q4w7-56hr-83rm</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1276 — nginx-ui: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1276</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um beliebigen Code mit Root-Rechten auszuführen, sich Administratorrechte zu verschaffen und die vollständige Kontrolle über das System zu erlangen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in nginx-ui ausnutzen, um beliebigen Code mit Root-Rechten auszuführen, sich Administratorrechte zu verschaffen und die vollständige Kontrolle über das System zu erlangen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1276</guid>
    </item>
  </channel>
</rss>
