cbcvebase.
CVE-2026-27654
published 2026-03-24

CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX…

PriorityP267high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
19.19%
97.0th percentile
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiannginx< nginx 1.28.3-1 (forky)nginx 1.28.3-1 (forky)
f5nginx>= 0 < 1.28.3-11.28.3-1
f5nginx_open_source
f5nginx_open_source>= 0.5.13 < 1.28.31.28.3
f5nginx_open_source0.5.13 – 0.9.7
f5nginx_open_source>= 1.0.0 < 1.28.31.28.3
f5nginx_open_source>= 1.29.0 < 1.29.71.29.7
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus
f5nginx_plus>= R32 < R32 P5R32 P5

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is exploitable only when NGINX configuration uses all three of: DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives — all three conditions must be present simultaneously
  • The vulnerability is in the ngx_http_dav_module module; audit NGINX configs for 'dav_methods MOVE' or 'dav_methods COPY' combined with 'alias' and non-regex location blocks to identify exposed instances
  • Successful exploitation may result in modification of source or destination file names outside the document root — monitor NGINX worker process file activity for path traversal outside the configured document root
  • ·Exploit requires a specific combination of three NGINX configuration directives: DAV MOVE/COPY methods enabled, a prefix (non-regex) location block, and an alias directive — deployments lacking any one of these three are not affected
  • ·Impact on system integrity is limited because the NGINX worker process runs with low privileges and does not have access to the entire system
  • ·NGINX versions that have reached End of Technical Support (EoTS) are not evaluated for this vulnerability

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_msrc8.2HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.