Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m468-xcm6-fxg4 | nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nginxui
Nginxui nginx Ui Uozi Uozi cosy |
|
| CPEs | cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* cpe:2.3:a:uozi:cosy:*:*:*:*:*:go:*:* |
|
| Vendors & Products |
Nginxui
Nginxui nginx Ui Uozi Uozi cosy |
|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
0xjacky
0xjacky nginx-ui |
|
| Vendors & Products |
0xjacky
0xjacky nginx-ui |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primary configuration file (app.ini). This vulnerability results in a persistent Denial of Service (DoS) and introduces a non-deterministic path for Remote Code Execution (RCE) through configuration cross-contamination. This issue has been patched in version 2.3.4. | |
| Title | Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-30T20:15:26.098Z
Reserved: 2026-03-17T17:22:14.669Z
Link: CVE-2026-33028
Updated: 2026-03-30T20:15:20.787Z
Status : Analyzed
Published: 2026-03-30T18:16:18.947
Modified: 2026-04-01T18:45:46.340
Link: CVE-2026-33028
No data.
OpenCVE Enrichment
Updated: 2026-04-02T07:54:08Z
Github GHSA