Vulnerabilities
Report: Update: CVE-2026-42223 - nginx-ui: Settings API Exposes Protected Secrets
CVE ID :CVE-2026-42223 Published : May 4, 2026, 9:16 p.m. | 58 minutes ago Description :Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected: