CVE-2026-61630 PUBLISHED

nginx ignition has TOTP Reuse During Validity Window

Assigner: GitHub_M
Reserved: 10.07.2026 Published: 21.09.2026 Updated: 21.09.2026

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 4.2

Product Status

Vendor lucasdillmann
Product nginx-ignition
Versions
  • Version >= 2.33.0, < 2.35.1 is affected

References

Problem Types

  • CWE-287: Improper Authentication CWE