
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32647 is a buffer over-read/over-write vulnerability in the ngx_http_mp4_module module of NGINX Open Source and NGINX Plus. An attacker who can trigger processing of a specially crafted MP4 file through the vulnerable module may cause NGINX worker process termination or potentially achieve arbitrary code execution. The vulnerability was published on March 24, 2026, and affects NGINX Open Source versions 1.1.19 through 1.28.2 and 1.29.0 through 1.29.6, as well as NGINX Plus R32 through R36 (various patch levels). It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (F5 Advisory, Red Hat CVE).
The root cause is classified as CWE-125 (Out-of-bounds Read), with the possibility of an over-write condition as well, within the ngx_http_mp4_module module. Exploitation requires local access (attack vector: local) with low privileges, and no user interaction — an attacker must be able to supply or trigger the processing of a maliciously crafted MP4 file by an NGINX instance that has both the ngx_http_mp4_module compiled in and the mp4 directive enabled in its configuration. The vulnerability is mapped to CAPEC-540 (Overread Buffers), indicating the attacker manipulates MP4 file metadata or structure to cause the NGINX worker to read or write beyond allocated memory boundaries (F5 Advisory, Red Hat CVE).
Successful exploitation can result in termination of the NGINX worker process (denial of service) or, in more severe cases, arbitrary code execution with the privileges of the NGINX worker process. Confidentiality, integrity, and availability are all rated High impact under CVSS v3.1. The scope is limited to the affected NGINX worker process and does not directly propagate to other system components, but code execution as the worker process could enable further lateral movement or data access depending on the deployment environment (F5 Advisory).
ngx_http_mp4_module and have the mp4 directive enabled in their configuration. This can be done by reviewing server responses or configuration files if accessible.ngx_http_mp4_module.GET /path/to/malicious.mp4) that causes NGINX to process the file through the vulnerable module./var/log/nginx/error.log (e.g., worker process exited on signal 11 indicating a segmentation fault); repeated HTTP requests for MP4 files from unusual or unexpected source IPs..mp4 files in directories served by NGINX with the mp4 module enabled; unexpected files written to NGINX working directories if code execution was achieved.Range headers.F5 has released patched versions: NGINX Open Source 1.28.3 (stable branch) and 1.29.7 (mainline branch); NGINX Plus R32 P5 or later, R35 P2 or later, and R36 P3 or later. Upgrading to a patched version is the recommended remediation. If immediate patching is not feasible, disable the mp4 directive in the NGINX configuration file to prevent the vulnerable code path from being triggered, or restrict access to MP4 processing endpoints to trusted sources only. Multiple Linux distribution vendors (Red Hat, SUSE, Ubuntu, Debian, Amazon Linux) have also released updated packages (F5 Advisory, Red Hat CVE, NGINX Releases).
Security news outlets including GBHackers, CyberSecurityNews, and SecurityOnline covered the vulnerability shortly after disclosure, highlighting the potential for remote code execution via MP4 file processing (GBHackers, CyberSecurityNews). The vulnerability was also discussed in the oss-security mailing list (oss-sec). Community reaction has been measured, with the primary focus on patching given the local attack vector requirement and absence of public exploits. The Hacker News weekly recap included the vulnerability in its threat landscape summary.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."