CVE-2026-33029: Nginxui Nginx UI

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enters an infinite loop or an invalid state, rendering the web interface unresponsive. This issue has been patched in version 2.3.4.

Affected products

  • Nginxui Nginx UI: before 2.3.4 (fixed in 2.3.4)

Published 2026-03-30. Last modified 2026-06-17.