Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-16845

26
FAUCET Score

CVE-2018-16845 is a medium-severity vulnerability affecting nginx versions prior to 1.15.6 and 1.14.1, specifically when built with the ngx_http_mp4_module and configured to process MP4 files. An attacker can exploit this by providing a specially crafted MP4 file, leading to an infinite loop, worker process crash, or memory disclosure. The attack requires local access, user interaction, and low attack complexity. While not actively exploited in the wild and lacking public exploit code, it has received some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.7, <= 1.0.15CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
>= 1.1.3, <= 1.15.5CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.2HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.0

Exploit Intelligence

EPSS Score
9.80%
Probability of exploitation in next 30 days
EPSS Percentile
95.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0980 is in the 98th percentile among its peer group of 5,765 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

dahuapatch availablevia llm_extracted
Fixed in: 1.14.1+
View patch
dfinitypatch availablevia llm_extracted
Fixed in: 1.15.6
View patch
jfrogpatch availablevia llm_extracted
Fixed in: 1.15.6
View patch
liferaypatch availablevia llm_extracted
Fixed in: 1.14.1
View patch
netgearpatch availablevia llm_extracted
Fixed in: 1.15.6+, 1.14.1+
View patch
opensshpatch availablevia llm_extracted
Fixed in: 1.15.6
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.14.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-nginx110-nginx-1:1.10.2-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-nginx112-nginx-1:1.12.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-nginx114-nginx-1:1.14.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nginx110-nginx-1:1.10.2-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nginx112-nginx-1:1.12.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-nginx18-nginx-1:1.8.1-1.el6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nginx110-nginx-1:1.10.2-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nginx112-nginx-1:1.12.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-nginx114-nginx-1:1.14.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-nginx114-nginx-1:1.14.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-nginx110-nginx-1:1.10.2-8.el6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx18-nginx-1:1.8.1-1.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx110-nginx-1:1.10.2-8.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx112-nginx-1:1.12.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx114-nginx-1:1.14.1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-nginx18-nginx-1:1.8.1-1.el7.1
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.15.6
View patch

Vendor Advisories (9)

redhatCVE-2018-16845Important

nginx: Denial of service and memory disclosure via mp4 module

Nov 6, 2018
opensshllm-openssh-417398a66b1da92dMEDIUM

Memory disclosure in the ngx_http_mp4_module

Jan 1, 2018
dfinityllm-dfinity-4b4ce7fa479d8d5dMEDIUM

Memory disclosure in the ngx_http_mp4_module

Jan 1, 2018
power_billm-power_bi-7725f0f951c0cd2dMEDIUM

Memory disclosure in the ngx_http_mp4_module

Jan 1, 2018
liferayllm-liferay-0be016a1c89ae644MEDIUM

Memory disclosure in the ngx_http_mp4_module

Jan 1, 2018
jfrogllm-jfrog-916a796756037c65MEDIUM

Memory disclosure in the ngx_http_mp4_module

Jan 1, 2018
dahuallm-dahua-96954f95d85f0747MEDIUM

Memory disclosure in the ngx_http_mp4_module

terraformllm-terraform-34d9212062c27183MEDIUM

Memory disclosure in the ngx_http_mp4_module

netgearllm-netgear-2c527f811569aed1MEDIUM

Memory disclosure in the ngx_http_mp4_module

References

lists.opensuse.org / opensuse-security-announce/2019-09/msg00035.html
Mailing ListThird Party Advisory
mailman.nginx.org / pipermail/nginx-announce/2018/000221.html
Mailing ListPatchVendor Advisory
access.redhat.com / errata/RHSA-2018:3652
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3653
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3680
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3681
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
seclists.org / fulldisclosure/2021/Sep/36
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2018/11/msg00010.html
Mailing ListThird Party Advisory
support.apple.com / kb/HT212818
Third Party Advisory
usn.ubuntu.com / 3812-1
PatchThird Party Advisory
debian.org / security/2018/dsa-4335
Third Party Advisory
securityfocus.com / bid/105868
Third Party AdvisoryVDB Entry
securitytracker.com / id/1042039
Third Party AdvisoryVDB Entry