CVE-2026-27654
published 2026-03-24CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX…
PriorityP267high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
19.19%
97.0th percentile
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.28.3-1 (forky) | nginx 1.28.3-1 (forky) |
| f5 | nginx | >= 0 < 1.28.3-1 | 1.28.3-1 |
| f5 | nginx_open_source | — | — |
| f5 | nginx_open_source | >= 0.5.13 < 1.28.3 | 1.28.3 |
| f5 | nginx_open_source | 0.5.13 – 0.9.7 | — |
| f5 | nginx_open_source | >= 1.0.0 < 1.28.3 | 1.28.3 |
| f5 | nginx_open_source | >= 1.29.0 < 1.29.7 | 1.29.7 |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R32 < R32 P5 | R32 P5 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploitable only when NGINX configuration uses all three of: DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives — all three conditions must be present simultaneously ↗
- →The vulnerability is in the ngx_http_dav_module module; audit NGINX configs for 'dav_methods MOVE' or 'dav_methods COPY' combined with 'alias' and non-regex location blocks to identify exposed instances ↗
- →Successful exploitation may result in modification of source or destination file names outside the document root — monitor NGINX worker process file activity for path traversal outside the configured document root ↗
- ·Exploit requires a specific combination of three NGINX configuration directives: DAV MOVE/COPY methods enabled, a prefix (non-regex) location block, and an alias directive — deployments lacking any one of these three are not affected ↗
- ·Impact on system integrity is limited because the NGINX worker process runs with low privileges and does not have access to the entire system ↗
- ·NGINX versions that have reached End of Technical Support (EoTS) are not evaluated for this vulnerability ↗
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_msrc8.2HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-03·CVSS 6.3
CVE-2026-1642 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that the nginx ngx_mail_smtp_module module incorrectly
handled certain memory operations when doing SMTP authentication. This
could possibly result in sensitive information being sent to the
authentication server. (CVE-2025-53859)
It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server. (CVE-2026-1642)
It was discovered that the nginx ngx_mail_auth_http_module module
incorrectly handled certain requests. An attacker could possibly use this
issue to cause nginx to crash, resulting in a denial of service.
(CVE-2026-27651)
It was discovered that
Red Hat
NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
vendor_redhat·2026-03-24·CVSS 8.8
CVE-2026-27654 [HIGH] CWE-120 NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which ha
F5
CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker ...
vendor_f5·2026-03-24·CVSS 8.2
CVE-2026-27654 [HIGH] CWE-122 CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker ...
CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker ...
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire
Microsoft
NGINX ngx_http_dav_module vulnerability
vendor_msrc·2026-03-10·CVSS 8.2
CVE-2026-27654 [HIGH] CWE-122 NGINX ngx_http_dav_module vulnerability
NGINX ngx_http_dav_module vulnerability
Mariner: Mariner
f5: f5
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-27654: nginx - NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module...
vendor_debian·2026·CVSS 8.8
CVE-2026-27654 [HIGH] CVE-2026-27654: nginx - NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module...
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Scope: local
bookworm: open
bullsey
VulDB
F5 NGINX Open Source/NGINX Plus DAV Module ngx_http_dav_module heap-based overflow (K000160382 / Nessus ID 305582)
vuldb·2026-04-14·CVSS 8.8
CVE-2026-27654 [HIGH] F5 NGINX Open Source/NGINX Plus DAV Module ngx_http_dav_module heap-based overflow (K000160382 / Nessus ID 305582)
A vulnerability identified as critical has been detected in F5 NGINX Open Source and NGINX Plus. Affected by this vulnerability is the function ngx_http_dav_module of the component DAV Module. The manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-27654. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
OSV
CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to t
osv·2026-03-24·CVSS 8.8
CVE-2026-27654 [HIGH] CVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to t
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA
GHSA-6r46-2qjx-j5j3: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to t
ghsa_unreviewed·2026-03-24
CVE-2026-27654 [HIGH] CWE-122 GHSA-6r46-2qjx-j5j3: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to t
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
blogs_hackernews·2026-04-27
CVE-2025-20333 ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are.
Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust. Same mess, cleaner packaging.
Coffee is cold. The vuln list is ugly. Let’s get into it.
## ⚡ Threat of the Week
New fast16 Malware Was Developed Y
Wiz
CVE-2026-27651 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-27651 [HIGH] CVE-2026-27651 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27651 :
NGINX vulnerability analysis and mitigation
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 8.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
NGINX
Nginx Plus
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.5
Exploitation Probability (EPSS) N/A
Affected
Wiz
CVE-2026-27784 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-27784 [HIGH] CVE-2026-27784 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27784 :
NGINX vulnerability analysis and mitigation
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 8.5
Score
Published March 24, 2026
Severity HIGH
CNA Score 8.
Wiz
CVE-2026-27654 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-27654 [HIGH] CVE-2026-27654 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27654 :
NGINX vulnerability analysis and mitigation
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Sup
Wiz
CVE-2026-1642 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2026-1642 [HIGH] CVE-2026-1642 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1642 :
NGINX vulnerability analysis and mitigation
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 8.2
Score
Published February 4, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
NGINX
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation
Wiz
CVE-2026-32647 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-32647 [HIGH] CVE-2026-32647 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32647 :
NGINX vulnerability analysis and mitigation
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 8.5
Score
Published M
Wiz
CVE-2026-28753 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28753 [HIGH] CVE-2026-28753 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28753 :
NGINX vulnerability analysis and mitigation
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 6.3
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
NGINX
Nginx Plus
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.4
Exploitation Probability (EPSS) N/A
Affected packages and lib
Wiz
CVE-2026-28755 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28755 [HIGH] CVE-2026-28755 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28755 :
NGINX vulnerability analysis and mitigation
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 5.3
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
NGINX
Nginx Plus
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affec
Bugzilla
CVE-2026-27654 NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
bugzilla·2026-03-24·CVSS 8.8
CVE-2026-27654 [HIGH] CVE-2026-27654 NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
CVE-2026-27654 NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software ve
Bugzilla
CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module [fedora-all]
bugzilla·2026-03-24·CVSS 8.8
CVE-2026-27654 [HIGH] CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module [fedora-all]
CVE-2026-27654 nginx: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-4de4d247a0 (nginx-1.28.3-1.fc44, nginx-mod-brotli-1.0.0~rc-7.fc44, and 5 more) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-4de4d247a0
---
FEDORA-2026-4de4d247a0 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-4de4d
https://my.f5.com/manage/s/article/K000160382https://access.redhat.com/errata/RHSA-2026:10065https://access.redhat.com/errata/RHSA-2026:13634https://access.redhat.com/errata/RHSA-2026:13680https://access.redhat.com/errata/RHSA-2026:13839https://access.redhat.com/errata/RHSA-2026:14836https://access.redhat.com/errata/RHSA-2026:15942https://access.redhat.com/errata/RHSA-2026:15943https://access.redhat.com/errata/RHSA-2026:15945https://access.redhat.com/errata/RHSA-2026:15966https://access.redhat.com/errata/RHSA-2026:6906https://access.redhat.com/errata/RHSA-2026:6907https://access.redhat.com/errata/RHSA-2026:6923https://access.redhat.com/errata/RHSA-2026:7002https://access.redhat.com/errata/RHSA-2026:7343https://access.redhat.com/errata/RHSA-2026:8346https://access.redhat.com/security/cve/CVE-2026-27654https://bugzilla.redhat.com/show_bug.cgi?id=2450776https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27654.json
2026-03-24
Published