
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27654 is a heap-based buffer overflow vulnerability in the ngx_http_dav_module of NGINX Open Source and NGINX Plus. It allows unauthenticated remote attackers to trigger a buffer overflow in the NGINX worker process, potentially causing worker process termination (denial of service) or modification of file names outside the document root. The vulnerability was published on March 24, 2026, and affects NGINX Open Source versions 0.5.13 through 1.28.2 and 1.29.0 through 1.29.6, as well as NGINX Plus R32 through R36 (various patch levels). It carries a CVSS v3.1 base score of 8.2 (High) and a CVSS v4.0 base score of 8.8 (High) (F5 Advisory, Red Hat CVE).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-120 (Buffer Copy without Checking Size of Input). It is triggered specifically when the NGINX configuration simultaneously uses the DAV module with MOVE or COPY methods, a prefix location (non-regular expression location block), and an alias directive — the combination of these three conditions allows an attacker to craft a malicious HTTP request that overflows a heap buffer in the NGINX worker process. The attack requires no authentication, no user interaction, and is exploitable over the network with low complexity (F5 Advisory, Feedly). Notably, this CVE was credited to Anthropic (AI-assisted vulnerability discovery), making it a notable case of AI-aided security research (VulnCheck Blog).
Successful exploitation can cause the NGINX worker process to crash, resulting in denial of service for all requests handled by that worker. Additionally, an attacker may be able to manipulate source or destination file names for MOVE or COPY operations, potentially writing files outside the configured document root. The integrity impact is constrained because the NGINX worker process runs with low privileges and does not have access to the broader system, limiting the scope of file manipulation. There is no confidentiality impact reported (F5 Advisory, Feedly).
ngx_http_dav_module enabled with MOVE or COPY methods, a prefix (non-regex) location block, and an alias directive — this specific combination is required for exploitation.Destination header or URI designed to overflow the heap buffer in the worker process during path resolution with the alias directive.Destination headers targeting prefix location paths.error.log) showing worker process crashes or segmentation faults; repeated [alert] or [crit] entries indicating worker process termination and restart cycles.F5 has released patched versions: NGINX Open Source 1.28.3 (stable branch) and 1.29.7 (mainline branch); NGINX Plus R32 P5, R33 P4, R34 P3, R35 P2, and R36 P3 (F5 Advisory). As an immediate workaround if patching cannot be applied, disable the DAV module MOVE and COPY methods in the NGINX configuration, or remove the combination of prefix location blocks with alias directives where DAV is enabled. Organizations should audit all NGINX configurations to identify instances using ngx_http_dav_module with the vulnerable directive combination. Red Hat, Ubuntu, SUSE, Debian, Amazon Linux, and other Linux distributions have also released updated packages (Red Hat Errata, Ubuntu USN).
The vulnerability attracted notable attention due to its attribution to Anthropic's AI systems as the discoverer, sparking community discussion about AI-assisted vulnerability research. A blog post titled "Claude Humans vs NGINX CVE-2026-27654" was widely shared on Reddit's r/netsec and r/blueteamsec communities, and security researcher grugq referenced it in his newsletter (Reddit r/netsec, VulnCheck Blog). Security media including The Hacker News, Risky Biz, and TLDR InfoSec covered the vulnerability in their weekly recaps. Sangfor's Farsight Labs and SecurityOnline.info published threat intelligence write-ups highlighting the DoS and potential RCE risk (Sangfor). The oss-security mailing list also received a disclosure post (oss-sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."