๐Ÿ” CVE Alert

CVE-2026-27784

HIGH 7.8

NGINX ngx_http_mp4_module vulnerability

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CWE CWE-190
Vendor f5
Product nginx open source
Published Mar 24, 2026
Last Updated Jul 15, 2026
Stay Ahead of the Next One

Get instant alerts for f5 nginx open source

Be the first to know when new high vulnerabilities affecting f5 nginx open source are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

F5 / NGINX Open Source
1.29.0 < 1.29.7 1.1.19 < 1.28.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
my.f5.com: https://my.f5.com/manage/s/article/K000160364 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-27784 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2450785 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27784.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13634 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6906 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6907 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:15942 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:14836 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13839 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:15943 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:15945 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:13680 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:15966 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6923 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:7002 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:7343 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:8346 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:10065

Credits

๐Ÿ” F5 acknowledges Prabhav Srinath (sprabhav7) for bringing this issue to our attention and following the highest standards of coordinated disclosure.