CVE-2026-27784
Published: March 25, 2026Last modified: March 31, 2026
Description
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.8 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | nginx | Fixed (1.22.1-r4) |
| 25 LTS | nginx | Fixed (1.28.3-r0) | |
| Stream | nginx | Fixed (1.28.3-r0) |
References
- https://access.redhat.com/errata/RHSA-2026:10065
- https://access.redhat.com/errata/RHSA-2026:13634
- https://access.redhat.com/errata/RHSA-2026:13680
- https://access.redhat.com/errata/RHSA-2026:13839
- https://access.redhat.com/errata/RHSA-2026:14836
- https://access.redhat.com/errata/RHSA-2026:15942
- https://access.redhat.com/errata/RHSA-2026:15943
- https://access.redhat.com/errata/RHSA-2026:15945
- https://access.redhat.com/errata/RHSA-2026:15966
- https://access.redhat.com/errata/RHSA-2026:6906
- https://access.redhat.com/errata/RHSA-2026:6907
- https://access.redhat.com/errata/RHSA-2026:6923
- https://access.redhat.com/errata/RHSA-2026:7002
- https://access.redhat.com/errata/RHSA-2026:7343
- https://access.redhat.com/errata/RHSA-2026:8346
- https://access.redhat.com/security/cve/CVE-2026-27784
- https://bugzilla.redhat.com/show_bug.cgi?id=2450785
- https://my.f5.com/manage/s/article/K000160364
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27784.json