nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| lucasdillmann | nginx-ignition | >= 2.33.0, < 2.35.1 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| lucasdillmann | nginx-ignition | >= 2.33.0, < 2.35.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61628 | 8.1 HIGH | nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition |
| CVE-2026-61629 | 7.5 HIGH | nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplifi |
No comments yet