Race condition in nginx-ui - CVE-2026-33028
Published: April 23, 2026
nginx-ui
Detailed vulnerability description
The vulnerability allows a remote user to cause persistent data corruption and a denial of service.
The vulnerability exists due to a race condition in the settings update pipeline when handling concurrent settings update requests. A remote privileged user can send concurrent crafted POST requests to /api/settings to cause persistent data corruption and a denial of service.
The issue can also cause cross-section contamination in app.ini, which may create a non-deterministic path to command execution if user-controlled values are written into command fields.