Description
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References (19)
Core 19
Core References
Vendor Advisory vendor-advisory
https://my.f5.com/manage/s/article/K000160364
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:10065
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:13634
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:13680
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:13839
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:14836
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:15942
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:15943
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:15945
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:15966
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:6906
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:6907
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:6923
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7002
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:7343
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:8346
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-27784
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2450785
Scores
CVSS v3
7.8
EPSS
0.0103
EPSS Percentile
60.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-190
Status
published
Products (3)
F5/NGINX Open Source
1.1.19 - 1.28.3
F5/NGINX Open Source
1.29.0 - 1.29.7
f5/nginx_open_source
1.1.19 - 1.28.3
Published
Mar 24, 2026
Tracked Since
Mar 24, 2026