CVE-2026-27654

HIGH EPSS 94.0%
Published Mar 24, 20263mo ago · Modified Jun 17, 20261w ago
8.8 CVSS 4.0
High
Find Similar
Published Mar 24, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Details

Base Score
8.8
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
94.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-122

Affected Products 19

VendorProductVersionRange
f5nginx_plusr32any
f5nginx_plusr32any
f5nginx_plusr32any
f5nginx_plusr32any
f5nginx_plusr33any
f5nginx_plusr33any
f5nginx_plusr33any
f5nginx_plusr33any
f5nginx_plusr34any
f5nginx_plusr34any
f5nginx_plusr34any
f5nginx_plusr35any
f5nginx_plusr35any
f5nginx_plusr36any
f5nginx_plusr36any
f5nginx_plusr36any
f5nginx_open_source*≥0.5.13  –  ≤0.9.7
f5nginx_open_source*≥1.0.0  –  <1.28.3
f5nginx_open_source*≥1.29.0  –  <1.29.7

References 1

  • my.f5.com https://my.f5.com/manage/s/article/K000160382
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.