CVE-2026-27654 is a high-severity buffer overflow vulnerability affecting NGINX Open Source and NGINX Plus, specifically within the ngx_http_dav_module when configured with MOVE or COPY methods, prefix location, and alias directives. This flaw is remotely exploitable with low attack complexity, requiring no privileges or user interaction. Successful exploitation could lead to the termination of the NGINX worker process, resulting in a high availability impact, and potentially allow modification of file names outside the document root, though integrity impact is constrained by low worker process privileges. With a CVSS score of 8.2, this vulnerability is not currently known to be actively exploited, nor is there public exploit code available. Community discussion and media coverage remain limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:* | ||
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:* | ||
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:* | ||
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:* | ||
r33CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
NGINX ngx_http_dav_module vulnerability
Mar 10, 2026Buffer overflow in ngx_http_dav_module
Jan 1, 2026Buffer overflow in ngx_http_dav_module
Buffer overflow in ngx_http_dav_module
Buffer overflow in ngx_http_dav_module