CVE-2026-27784 is a high-severity vulnerability (CVSS 7.8) affecting the 32-bit implementation of NGINX Open Source when configured to use the ngx_http_mp4_module. An attacker can exploit this by providing a specially crafted MP4 file, leading to memory over-read or over-write and subsequent termination of the NGINX worker process. This local attack requires low privileges and has a high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no public exploit code available, the vulnerability has been mentioned in community discussions and security patch releases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.19, < 1.28.3CPE matchmatch criteria | cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* | ||
>= 1.29.0, < 1.29.7CPE matchmatch criteria | cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
NGINX ngx_http_mp4_module vulnerability
Mar 10, 2026Buffer overflow in the ngx_http_mp4_module
Jan 1, 2026Buffer overflow in the ngx_http_mp4_module
Buffer overflow in the ngx_http_mp4_module
Buffer overflow in the ngx_http_mp4_module