CVE-2026-61630: nginx ignition has TOTP Reuse During Validity Window
Any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window.
References
- github.com/advisories/GHSA-hf33-q6cf-c66f
- github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e
- github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107
- github.com/lucasdillmann/nginx-ignition/pull/104
- github.com/lucasdillmann/nginx-ignition/releases/tag/2.35.1
- github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f
- github.com/pquerna/otp/issues/61
- nvd.nist.gov/vuln/detail/CVE-2026-61630
Code Behaviors & Features
Detect and mitigate CVE-2026-61630 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →