
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27784 is an integer overflow vulnerability in the ngx_http_mp4_module module of 32-bit NGINX Open Source that may allow an attacker to over-read or over-write NGINX worker memory, potentially resulting in worker process termination. It was published on March 24, 2026, and affects NGINX Open Source versions 1.1.19 through 1.28.2 and 1.29.0 through 1.29.6. The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound) and carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 8.5 (High) (RedHat CVE, F5 Advisory).
The root cause is an integer overflow or wraparound (CWE-190) in the ngx_http_mp4_module module, specifically within the 32-bit build of NGINX Open Source. When processing a specially crafted MP4 file, integer arithmetic in the module can overflow, causing the server to over-read or over-write memory in the NGINX worker process. Exploitation requires three preconditions: (1) NGINX must be compiled as a 32-bit binary, (2) the ngx_http_mp4_module must be included at build time, and (3) the mp4 directive must be active in the configuration file. The attack vector is local (AV:L) with low privileges required, meaning an attacker must be able to supply a malicious MP4 file for processing by the module (F5 Advisory, RedHat CVE).
Successful exploitation can result in confidentiality breach through over-reading of NGINX worker memory, integrity compromise through over-writing of worker memory, and availability impact through termination of NGINX worker processes. The attack surface is limited to 32-bit NGINX deployments with the MP4 module explicitly configured and accessible to process untrusted MP4 files. There is no evidence of lateral movement potential beyond the affected worker process scope (F5 Advisory).
ngx_http_mp4_module and the mp4 directive enabled in its configuration.mp4 directive (e.g., a video streaming endpoint using mp4 pseudo-streaming)./var/log/nginx/error.log (e.g., worker process exited on signal); repeated requests to MP4 streaming endpoints with unusual or malformed file parameters.nginx: worker process entries visible via ps or system logs.?start= parameters) from a single source with varying or oversized MP4 files..mp4 files in directories served by NGINX with the mp4 directive enabled.F5/NGINX has released patched versions: NGINX Open Source 1.28.3 (stable branch) and 1.29.7 (mainline branch). Organizations should upgrade to one of these versions as the primary remediation. If immediate patching is not possible, the following workarounds are recommended: (1) remove or comment out the mp4 directive from the NGINX configuration and reload the service, (2) restrict access to MP4 processing endpoints to trusted sources only via firewall or NGINX allow/deny directives, and (3) consider deploying 64-bit NGINX builds, which are not affected by this vulnerability. Red Hat has also issued errata (e.g., RHSA-2026:6906, RHSA-2026:6907, RHSA-2026:6923) for affected RHEL packages (F5 Advisory, RedHat CVE).
The vulnerability received coverage from security news outlets including SecurityOnline.info and SecureReading.com, which described it as part of a broader set of NGINX vulnerabilities with potential for DoS and memory corruption. The Hacker Wire posted about it on Mastodon shortly after disclosure. Multiple Linux distributions (Red Hat, SUSE, Ubuntu, Debian, Amazon Linux, openSUSE) issued security advisories and package updates in the weeks following disclosure, reflecting broad ecosystem attention. Community discussion was measured, consistent with the limited attack surface imposed by the 32-bit-only constraint (SecurityOnline, RedHat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."