All 3 CVE vulnerabilities found in nginx-ignition, with AI-generated Chinese analysis, references, and POCs.
Vendor: lucasdillmann
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-61628 | nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition CWE-362 | 8.1 | High | 2026-09-21 |
| CVE-2026-61629 | nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware CWE-770 | 7.5 | High | 2026-09-21 |
| CVE-2026-61630 | nginx ignition has TOTP Reuse During Validity Window CWE-287 | 4.2 | Medium | 2026-09-21 |
All 3 known CVE vulnerabilities affecting nginx-ignition with full Chinese analysis, references, and POCs where available.