Executive brief
Nginx UI is a web-based management interface for the Nginx web server. A security vulnerability allows logged-in users to force the server to make requests to internal systems that are normally protected by firewalls. This could allow an attacker to access sensitive internal data, steal cloud credentials from metadata services, or gain a foothold for further attacks on the internal network.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Nginx UI Cluster Proxy middleware (internal/middleware/proxy.go). Authenticated attackers can retrieve the 'node_secret' from the settings API and then create a malicious cluster node pointing to an internal URL (e.g., localhost, internal IPs, or cloud metadata endpoints). By sending subsequent API requests with the 'X-Node-ID' header set to the malicious node's ID, the Proxy middleware forwards the request to the attacker-specified internal address without validation. This allows for network segmentation bypass, internal port scanning, and potential remote code execution when combined with other vulnerabilities. As of the advisory date, no patched version has been identified.
Affected products
- 0xJacky Nginx UI <= 2.3.4
Timeline
- 2026-04-22: advisory: Original GitHub security advisory published
- 2026-05-12: disclosed: CVE published to NVD