
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33028 is a race condition vulnerability in the nginx-ui web management application that leads to persistent configuration file corruption and service collapse. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes in the settings update pipeline, concurrent requests corrupt the primary configuration file (app.ini), resulting in persistent Denial of Service (DoS) and a non-deterministic path to Remote Code Execution (RCE). Affected software includes nginx-ui versions ≤ 2.3.3 and the dependency github.com/uozi-tech/cosy versions < 1.30.1. The vulnerability was published on March 28, 2026, and assigned a CVSS v4 base score of 7.1 (High) (Github Advisory, Security Advisory).
The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization). The settings update handler (POST /api/settings) lacks any synchronization primitives, allowing concurrent requests to simultaneously invoke ProtectedFill(), which modifies shared global singleton pointers without thread-safety, and trigger concurrent writes via gopkg.in/ini.v1, which performs direct file overwrites rather than atomic operations. At the OS level, interleaved write operations produce app.ini files with empty leading lines, truncated fields, or partially overwritten keys — and critically, INI sections can become cross-contaminated (e.g., nginx ReloadCmd values written into the [webauthn] section). An attacker requires a valid authenticated session with settings-update permissions, but no additional preconditions are needed (Github Advisory, Security Advisory).
Successful exploitation causes permanent corruption of app.ini, rendering the nginx-ui service unable to pass its "is-installed" check or causing fatal errors during boot/runtime — a persistent DoS that cannot be recovered through the web UI. Beyond availability, integrity is severely impacted as system-level configuration values (e.g., ConfigDir, ReloadCmd, RestartCmd) can be corrupted or cross-contaminated. In a non-deterministic but plausible scenario, an attacker-controlled string injected into a user-facing field (e.g., Node Name) could be cross-contaminated into a shell command field such as ReloadCmd, leading to RCE upon the next nginx reload (Security Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, with detailed step-by-step instructions using Burp Suite Intruder to send 20–50 concurrent POST /api/settings requests. The advisory has been assessed as a real exploit with high confidence by Feedly threat intelligence. There is no evidence of in-the-wild exploitation at this time, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.092% (26th percentile), indicating low but non-negligible exploitation probability (Github Advisory, Security Advisory).
POST /api/settings request.POST /api/settings HTTP request, including all required authentication headers and session tokens.app.ini file on the server — it will exhibit empty leading lines, truncated key-value pairs, or cross-contaminated INI sections (e.g., nginx ReloadCmd appearing under [webauthn])./install and becomes unrecoverable via the UI (persistent DoS), (b) the Go runtime or INI parser encounters a fatal error causing total service collapse, or (c) a user-controlled value is cross-contaminated into ReloadCmd/RestartCmd, executing arbitrary commands on the next nginx reload (Security Advisory).POST /api/settings requests from a single source IP within a short time window (20–50 simultaneous requests); unusual spikes in HTTP 500 or redirect responses from the nginx-ui API.app.ini containing empty leading lines, truncated key-value pairs, or misplaced configuration keys (e.g., ConfigDir, ReloadCmd appearing under [webauthn] section); presence of app.ini.tmp partial write artifacts./install; Go runtime panic stack traces in service logs; repeated failed "is-installed" checks.Upgrade nginx-ui to version 2.3.4 or later, which includes security patches addressing this vulnerability. For the dependency, upgrade github.com/uozi-tech/cosy to version 1.30.1 or later. As interim mitigations, restrict access to the POST /api/settings endpoint to only trusted administrator accounts, and implement rate limiting on concurrent requests to the settings handler. The recommended code-level fix involves wrapping ProtectedFill() and settings.Save() calls in a sync.Mutex and adopting an atomic write-then-rename strategy (write to app.ini.tmp, then use os.Rename()) (Security Advisory, v2.3.4 Release).
The vulnerability was reported by researcher "dapickle" and published by 0xJacky (the nginx-ui maintainer) on March 28, 2026. The v2.3.4 release notes explicitly state it includes "several security patches" and recommend all users update immediately. No significant broader media coverage or notable social media commentary beyond the GitHub advisory ecosystem has been identified (v2.3.4 Release, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."