High severity7.8NVD Advisory· Published Mar 24, 2026· Updated Jul 15, 2026
CVE-2026-27784
CVE-2026-27784
Description
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
19- F5/NGINX Open Sourcev5Range: 1.29.0
- osv-coords17 versionspkg:bitnami/nginx-gatewaypkg:apk/chainguard/nginx-mainlinepkg:apk/chainguard/nginx-stablepkg:apk/wolfi/nginx-mainlinepkg:apk/wolfi/nginx-stablepkg:bitnami/nginxpkg:rpm/almalinux/nginx-all-modulespkg:rpm/almalinux/nginx-filesystempkg:rpm/almalinux/nginxpkg:rpm/almalinux/nginx-mod-develpkg:rpm/almalinux/nginx-mod-http-image-filterpkg:rpm/almalinux/nginx-mod-http-perlpkg:rpm/almalinux/nginx-mod-http-xslt-filterpkg:rpm/almalinux/nginx-mod-mailpkg:rpm/almalinux/nginx-mod-streampkg:rpm/almalinux/nginx-corepkg:rpm/opensuse/nginx&distro=openSUSE%20Tumbleweed
>= 1.1.19, < 1.28.3+ 16 more
- (no CPE)range: >= 1.1.19, < 1.28.3
- (no CPE)range: < 1.29.7-r0
- (no CPE)range: < 1.28.3-r0
- (no CPE)range: < 1.29.7-r0
- (no CPE)range: < 1.28.3-r0
- (no CPE)range: >= 1.1.19, < 1.28.3
- (no CPE)range: < 2:1.26.3-2.el10_1.1
- (no CPE)range: < 2:1.26.3-2.el10_1.1
- (no CPE)range: < 1:1.24.0-3.module_el8.10.0+4159+021b4a2a.alma.1
- (no CPE)range: < 1:1.24.0-3.module_el8.10.0+4159+021b4a2a.alma.1
- (no CPE)range: < 1:1.24.0-3.module_el8.10.0+4159+021b4a2a.alma.1
- (no CPE)range: < 1:1.24.0-3.module_el8.10.0+4159+021b4a2a.alma.1
- (no CPE)range: < 1:1.24.0-3.module_el8.10.0+4159+021b4a2a.alma.1
- (no CPE)range: < 1:1.24.0-3.module_el8.10.0+4159+021b4a2a.alma.1
- (no CPE)range: < 1:1.24.0-3.module_el8.10.0+4159+021b4a2a.alma.1
- (no CPE)range: < 1:1.24.0-5.module_el9.7.0+220+47ec8b91.2.alma.1
- (no CPE)range: < 1.29.7-1.1
Patches
Vulnerability mechanics
References
19- my.f5.com/manage/s/article/K000160364nvdMitigationVendor Advisory
- access.redhat.com/errata/RHSA-2026:10065nvd
- access.redhat.com/errata/RHSA-2026:13634nvd
- access.redhat.com/errata/RHSA-2026:13680nvd
- access.redhat.com/errata/RHSA-2026:13839nvd
- access.redhat.com/errata/RHSA-2026:14836nvd
- access.redhat.com/errata/RHSA-2026:15942nvd
- access.redhat.com/errata/RHSA-2026:15943nvd
- access.redhat.com/errata/RHSA-2026:15945nvd
- access.redhat.com/errata/RHSA-2026:15966nvd
- access.redhat.com/errata/RHSA-2026:6906nvd
- access.redhat.com/errata/RHSA-2026:6907nvd
- access.redhat.com/errata/RHSA-2026:6923nvd
- access.redhat.com/errata/RHSA-2026:7002nvd
- access.redhat.com/errata/RHSA-2026:7343nvd
- access.redhat.com/errata/RHSA-2026:8346nvd
- access.redhat.com/security/cve/CVE-2026-27784nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27784.jsonnvd
News mentions
0No linked articles in our index yet.