CVE-2026-32647 is a high-severity vulnerability affecting NGINX Open Source and NGINX Plus when configured with the ngx_http_mp4_module. An attacker can trigger a buffer over-read or over-write using a specially crafted MP4 file, potentially leading to NGINX worker termination or arbitrary code execution. This issue carries a CVSS score of 7.8 (High), indicating low attack complexity and high impact on system availability, confidentiality, and integrity. While there is no known public exploit code or evidence of active exploitation, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:* | ||
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:* | ||
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:* | ||
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:* | ||
r33CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
NGINX ngx_http_mp4_module vulnerability
Mar 10, 2026Buffer overflow in the ngx_http_mp4_module
Jan 1, 2026Buffer overflow in the ngx_http_mp4_module
Buffer overflow in the ngx_http_mp4_module
Buffer overflow in the ngx_http_mp4_module