Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/lucasdillmann/nginx-ignition
  4. ›
  5. CVE-2026-61630

CVE-2026-61630: nginx ignition has TOTP Reuse During Validity Window

September 21, 2026

Any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window.

References

  • github.com/advisories/GHSA-hf33-q6cf-c66f
  • github.com/lucasdillmann/nginx-ignition/commit/1cbfae0296f1b186158f5a294ec484060e00102e
  • github.com/lucasdillmann/nginx-ignition/commit/8d35e1eb5dd6a40fef94a45511fe08b0603af107
  • github.com/lucasdillmann/nginx-ignition/pull/104
  • github.com/lucasdillmann/nginx-ignition/releases/tag/2.35.1
  • github.com/lucasdillmann/nginx-ignition/security/advisories/GHSA-hf33-q6cf-c66f
  • github.com/pquerna/otp/issues/61
  • nvd.nist.gov/vuln/detail/CVE-2026-61630

Code Behaviors & Features

Detect and mitigate CVE-2026-61630 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.0.0-20260217145239-1cbfae0296f1 before 0.0.0-20260328015550-8d35e1eb5dd6

Fixed versions

  • 0.0.0-20260328015550-8d35e1eb5dd6

Solution

Upgrade to version 0.0.0-20260328015550-8d35e1eb5dd6 or above.

Impact 4.2 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication

Source file

go/github.com/lucasdillmann/nginx-ignition/CVE-2026-61630.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:22:13 +0000.