CVE-2026-27784Integer Overflow or Wraparound in F5 Nginx Open Source

Severity
8.5HIGHNVD
EPSS
0.0%
top 98.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24

Description

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages4 packages

CVEListV5f5/nginx_open_source1.29.01.29.7+1
NVDf5/nginx_open_source1.1.191.28.3+1
Alpinef5/nginx< 1.28.3-r0+1
Debianf5/nginx< 1.28.3-1

🔴Vulnerability Details

4
OSV
CVE-2026-27784: The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or ov2026-03-24
GHSA
GHSA-hwq5-42j9-jvqj: The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or ov2026-03-24
CVEList
NGINX ngx_http_mp4_module vulnerability2026-03-24
OSV
CVE-2026-27784: The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or ov2026-03-24

📋Vendor Advisories

4
F5
CVE-2026-27784: The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might all...2026-03-24
Red Hat
NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file2026-03-24
Microsoft
NGINX ngx_http_mp4_module vulnerability2026-03-10
Debian
CVE-2026-27784: nginx - The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_ht...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-27784 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-27784 NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file2026-03-24
CVE-2026-27784 — Integer Overflow or Wraparound in F5 | cvebase