---
id: CVE-2026-61630
title: nginx ignition is a user interface for the nginx web server
summary: >-
  nginx ignition is a user interface for the nginx web server. In versions
  2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their
  TOTP reused during the standard 30 second validity window. Version 2.35.1
  patches the is…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-287
vendor: lucasdillmann
product: github.com/lucasdillmann/nginx-ignition
affected:
  - >-
    github.com/lucasdillmann/nginx-ignition >=
    0.0.0-20260217145239-1cbfae0296f1, < 0.0.0-20260328015550-8d35e1eb5dd6
patched:
  - github.com/lucasdillmann/nginx-ignition 0.0.0-20260328015550-8d35e1eb5dd6
published: '2026-09-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:25:27.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61630'
references:
  - url: >-
      https://github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e
    label: security-advisories@github.com
  - url: >-
      https://github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107
    label: security-advisories@github.com
  - url: >-
      https://github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61630'
  - url: 'https://github.com/pquerna/otp/issues/61'
  - url: 'https://github.com/lucasdillmann/nginx-ignition/pull/104'
  - url: 'https://github.com/lucasdillmann/nginx-ignition/releases/tag/2.35.1'
  - url: 'https://github.com/advisories/GHSA-hf33-q6cf-c66f'
  - url: 'https://github.com/lucasdillmann/nginx-ignition'
tags:
  - nvd
  - ghsa
  - go
  - cve.org
  - osv
epss: 0.00381
epssPercentile: 0.29226
aliases:
  - GHSA-hf33-q6cf-c66f
ecosystem: go
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T19:40:23.551843Z'
ingestedAt: '2026-09-21T14:38:56.368Z'
---

## Overview

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-61630)

Affected packages:

- `github.com/lucasdillmann/nginx-ignition >= 0.0.0-20260217145239-1cbfae0296f1, < 0.0.0-20260328015550-8d35e1eb5dd6`

Patched in:

- `github.com/lucasdillmann/nginx-ignition 0.0.0-20260328015550-8d35e1eb5dd6`

Source: https://github.com/advisories/GHSA-hf33-q6cf-c66f
