Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypassing network segmentation and enabling access to services bound to localhost or internal networks.
References
| Link | Resource |
|---|---|
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-wr32-99hh-6f35 | Exploit Vendor Advisory |
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-wr32-99hh-6f35 | Exploit Vendor Advisory |
Configurations
History
14 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-wr32-99hh-6f35 - Exploit, Vendor Advisory |
14 May 2026, 14:49
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-wr32-99hh-6f35 - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* | |
| First Time |
Nginxui
Nginxui nginx Ui |
12 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 22:16
Updated : 2026-05-14 22:16
NVD link : CVE-2026-44015
Mitre link : CVE-2026-44015
CVE.ORG link : CVE-2026-44015
JSON object : View
Products Affected
nginxui
- nginx_ui
CWE
CWE-918
Server-Side Request Forgery (SSRF)
