CVE-2026-33028: 
Nginx UI vulnerability analysis and mitigation

Overview

CVE-2026-33028 is a race condition vulnerability in the nginx-ui web management application that leads to persistent configuration file corruption and service collapse. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes in the settings update pipeline, concurrent requests corrupt the primary configuration file (app.ini), resulting in persistent Denial of Service (DoS) and a non-deterministic path to Remote Code Execution (RCE). Affected software includes nginx-ui versions ≤ 2.3.3 and the dependency github.com/uozi-tech/cosy versions < 1.30.1. The vulnerability was published on March 28, 2026, and assigned a CVSS v4 base score of 7.1 (High) (Github Advisory, Security Advisory).

Technical details

The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization). The settings update handler (POST /api/settings) lacks any synchronization primitives, allowing concurrent requests to simultaneously invoke ProtectedFill(), which modifies shared global singleton pointers without thread-safety, and trigger concurrent writes via gopkg.in/ini.v1, which performs direct file overwrites rather than atomic operations. At the OS level, interleaved write operations produce app.ini files with empty leading lines, truncated fields, or partially overwritten keys — and critically, INI sections can become cross-contaminated (e.g., nginx ReloadCmd values written into the [webauthn] section). An attacker requires a valid authenticated session with settings-update permissions, but no additional preconditions are needed (Github Advisory, Security Advisory).

Impact

Successful exploitation causes permanent corruption of app.ini, rendering the nginx-ui service unable to pass its "is-installed" check or causing fatal errors during boot/runtime — a persistent DoS that cannot be recovered through the web UI. Beyond availability, integrity is severely impacted as system-level configuration values (e.g., ConfigDir, ReloadCmd, RestartCmd) can be corrupted or cross-contaminated. In a non-deterministic but plausible scenario, an attacker-controlled string injected into a user-facing field (e.g., Node Name) could be cross-contaminated into a shell command field such as ReloadCmd, leading to RCE upon the next nginx reload (Security Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, with detailed step-by-step instructions using Burp Suite Intruder to send 20–50 concurrent POST /api/settings requests. The advisory has been assessed as a real exploit with high confidence by Feedly threat intelligence. There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.092% (26th percentile), indicating low but non-negligible exploitation probability (Github Advisory, Security Advisory).

Exploitation steps

  1. Authenticate: Log in to the nginx-ui dashboard using valid credentials with settings-update permissions.
  2. Navigate to target: Go to the Preferences section and make a settings change to generate a valid POST /api/settings request.
  3. Capture the request: Use Burp Suite (or similar proxy) to intercept the POST /api/settings HTTP request, including all required authentication headers and session tokens.
  4. Configure concurrent attack: Send the captured request to Burp Suite Intruder. Set the payload type to "Null payloads" (for basic concurrency testing) or a fuzzing list (for data-driven corruption). Configure the Resource Pool to use 20–50 concurrent threads.
  5. Launch the attack: Start the Intruder attack, flooding the settings handler with simultaneous requests to trigger the race condition.
  6. Observe corruption: Monitor the app.ini file on the server — it will exhibit empty leading lines, truncated key-value pairs, or cross-contaminated INI sections (e.g., nginx ReloadCmd appearing under [webauthn]).
  7. Achieve DoS or RCE: Depending on corruption outcome — (a) the service redirects to /install and becomes unrecoverable via the UI (persistent DoS), (b) the Go runtime or INI parser encounters a fatal error causing total service collapse, or (c) a user-controlled value is cross-contaminated into ReloadCmd/RestartCmd, executing arbitrary commands on the next nginx reload (Security Advisory).

Indicators of compromise

  • Network: Burst of concurrent POST /api/settings requests from a single source IP within a short time window (20–50 simultaneous requests); unusual spikes in HTTP 500 or redirect responses from the nginx-ui API.
  • File System: app.ini containing empty leading lines, truncated key-value pairs, or misplaced configuration keys (e.g., ConfigDir, ReloadCmd appearing under [webauthn] section); presence of app.ini.tmp partial write artifacts.
  • Logs: nginx-ui application logs showing fatal INI parse errors or repeated redirects to /install; Go runtime panic stack traces in service logs; repeated failed "is-installed" checks.
  • Process: nginx-ui process crashing or becoming unresponsive; unexpected nginx reload or restart commands executing with anomalous arguments (Security Advisory).

Mitigation and workarounds

Upgrade nginx-ui to version 2.3.4 or later, which includes security patches addressing this vulnerability. For the dependency, upgrade github.com/uozi-tech/cosy to version 1.30.1 or later. As interim mitigations, restrict access to the POST /api/settings endpoint to only trusted administrator accounts, and implement rate limiting on concurrent requests to the settings handler. The recommended code-level fix involves wrapping ProtectedFill() and settings.Save() calls in a sync.Mutex and adopting an atomic write-then-rename strategy (write to app.ini.tmp, then use os.Rename()) (Security Advisory, v2.3.4 Release).

Community reactions

The vulnerability was reported by researcher "dapickle" and published by 0xJacky (the nginx-ui maintainer) on March 28, 2026. The v2.3.4 release notes explicitly state it includes "several security patches" and recommend all users update immediately. No significant broader media coverage or notable social media commentary beyond the GitHub advisory ecosystem has been identified (v2.3.4 Release, Github Advisory).

Additional resources


Source: This report was generated using AI

Related Nginx UI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44015CRITICAL9.9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 12, 2026
CVE-2026-42222CRITICAL9.8
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026
CVE-2026-42221CRITICAL9.8
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42238CRITICAL9
  • Nginx UI logoNginx UI
  • cpe:2.3:a:nginxui:nginx_ui
NoYesMay 04, 2026
CVE-2026-42223MEDIUM6.5
  • Nginx UI logoNginx UI
  • github.com/0xJacky/Nginx-UI
NoYesMay 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management