← Back to browse · API

CVE-2026-27654

Severity
HIGH
CVSS
8.8
EPSS
0.21747
Risk score
42.81
CISA KEV
No
PoC
Yes
Published
2026-03-24
Modified
2026-07-15
First seen
2026-08-07
Aliases
EUVD-2026-14881, GHSA-6R46-2QJX-J5J3
Products
F5:NGINX Open Source 0.5.13 <1.28.3, F5:NGINX Open Source 1.29.0 <1.29.7, F5:NGINX Plus R32 <R32 P5, F5:NGINX Plus R33 <*, F5:NGINX Plus R34 <*, F5:NGINX Plus R35 <R35 P2, F5:NGINX Plus R36 <R36 P3, linux, ubuntu
Sources
packetstorm 7e276815edbf21e19317468c|CVE-2026-27654
euvd EUVD-2026-14881
packetstorm d6075c181a25a2ebb290e6b8|CVE-2026-27654

Description

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References