SCA: security update for github.com/lucasdillmann/nginx-ignition (GHSA-hf33-q6cf-c66f)

medium Tenable Self-Hosted Container Security Plugin ID 448252

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user
that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window.
Version 2.35.1 patches the issue. (CVE-2026-61630)

Solution

Update the github.com/lucasdillmann/nginx-ignition library and its related packages to version 0.0.0-20260328015550-8d35e1eb5dd6 or later.

See Also

https://github.com/advisories/GHSA-hf33-q6cf-c66f

Plugin Details

Severity: Medium

ID: 448252

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/23/2026

Updated: 9/23/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:N/AC:H/Au:M/C:C/I:N/A:N

CVSS Score Source: CVE-2026-61630

CVSS v3

Risk Factor: Medium

Base Score: 4.2

Temporal Score: 3.7

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/21/2026

Vulnerability Publication Date: 9/21/2026

Reference Information

CVE: CVE-2026-61630

cwe: CWE-287