CRLF injection in nginx-ui - CVE-2024-23828
Published: January 28, 2024 / Updated: April 23, 2026
nginx-ui
Nginx UI
Description
The vulnerability allows a remote user to execute arbitrary code on the host.
The vulnerability exists due to improper neutralization of CRLF sequences in application configuration handling in app.ini when processing user-supplied input. A remote user can inject crafted input to modify test_config_cmd and start_cmd to execute arbitrary code on the host.