nginx ignition has TOTP Reuse During Validity Window
Summary
| CVE | CVE-2026-61630 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-21 15:17:30 UTC |
| Updated | 2026-09-21 21:17:06 UTC |
| Description | nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue. |
Risk And Classification
Primary CVSS: v3.1 4.2 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
EPSS: 0.002320000 probability, percentile 0.142970000 (date 2026-09-22)
Problem Types: CWE-287 | CWE-287 CWE-287: Improper Authentication
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.2 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 4.2 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
HighUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Lucasdillmann | Nginx-ignition | affected >= 2.33.0, < 2.35.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6... | [email protected] | github.com | |
| github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294... | [email protected] | github.com | |
| github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a4551... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.