CVE-2026-34403Disclosure(nginxui / nginx_ui)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijacking (CSWSH). Combined with the fact that authentication tokens are stored in browser cookies (set via JavaScript without HttpOnly or explicit SameSite attributes), a malicious webpage can establish authenticated WebSocket connections to the nginx-ui instance when a logged-in administrator visits the attacker-controlled page. Version 2.3.5 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1385

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ui

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
nginx_ui

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-21: 2Technical Details · 2026-04-21: 204-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 nginx-ui, Cross-Site WebSocket Hijacking (CSWSH), #CVE-2026-34403 (Critical) https://dailycve.com/nginx-ui-cross-site-websocket-hijacking-cswsh-cve-2026-34403-critical/

    Post summary

    The post announces the critical CVE‑2026‑34403 affecting nginx‑ui, describing it as a Cross‑Site WebSocket Hijacking vulnerability, but provides no details on PoC, exploitation, patches, or active attacks.

    0000040
    183 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34403 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrig… https://www.cve.org/CVERecord?id=CVE-2026-34403

    Post summary

    The post references CVE-2026-34403, noting that pre‑2.3.5 Nginx UI WebSocket endpoints use a gorilla/websocket Upgrader with improper CheckOrigin handling, but it provides no PoC, exploit, patch, or active‑exploitation details.

    0000076
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnginxuinginx_ui---

Explore more