{"id":"CVE-2026-33027","aliases":["GHSA-m8p8-53vf-8357","GO-2026-4907"],"url":"https://o3.security/vulnerability/CVE-2026-33027","summary":"Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory","details":"Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire /etc/nginx directory, resulting in a partial Denial of Service. This issue has been patched in version 2.3.4.","published":"2026-03-30T17:59:30.926Z","modified":"2026-08-05T03:32:13.385044659Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/0xJacky/Nginx-UI","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4"},{"type":"ADVISORY","url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-m8p8-53vf-8357"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33027.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33027"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-05T03:32:13.385044659Z"}}