CVE-2026-27654Disclosure(f5 / nginx_open_source)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch f5 nginx_open_source systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

4.3/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-122CWE-120

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_open_source
  • nginx_plus

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 25 mentions across 11 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 13 signals
  • Disclosure: 11 classified signals
  • General: 3 classified signals
  • Peaked 9d ago at 9 mentions (2026-03-26); latest day: 1
  • 25 total mentions across 11 days

Affected systems

Vendors
Products
nginx_open_sourcenginx_plus

5 versions affected across 2 products

Deep dive

Activity timeline25 mentions / 11d
02579Mentions · 2026-03-24: 4Mentions · 2026-03-26: 9Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-04-08: 1Mentions · 2026-04-10: 1Mentions · 2026-04-11: 4Mentions · 2026-04-13: 1Mentions · 2026-05-20: 1Mentions · 2026-06-16: 1Mentions · 2026-08-24: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-11: 2Exploit Tool / Code · 2026-04-08: 1Patch / Workaround · 2026-03-26: 8Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-11: 2Patch / Workaround · 2026-04-13: 1Technical Details · 2026-03-24: 4Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-11: 2Technical Details · 2026-04-13: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-16: 1Technical Details · 2026-08-24: 103-2403-2603-2903-3004-0804-1004-1104-1305-2006-1608-24
Signal classification4 categories
Disclosure
1144.0%
Patch
1040.0%
General
312.0%
Exploit
14.0%
Referenced assets26 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-244
Disclosure4
2026-03-269
Disclosure1Patch8
2026-03-291
Patch1
2026-03-301
General1
2026-04-081
Exploit1
2026-04-101
General1
2026-04-114
Disclosure2General1Patch1
2026-04-131
Disclosure1
2026-05-201
Disclosure1
2026-06-161
Disclosure1
2026-08-241
Disclosure1
Full discourse20 posts
  • Calif@calif_io
    General

    Claude + Humans vs nginx: CVE-2026-27654 We'd like to acknowledge Claude, Anthropic Research, NGINX developers and F5 PSIRT for partnering with us on this. It was a pleasant experience. https://open.substack.com/pub/calif/p/claude-humans-vs-nginx-cve-2026-27654?r=26yra9&utm_campaign=post&utm_medium=web

    Post summary

    The post acknowledges collaboration on CVE‑2026‑27654 but does not provide specifics on PoC, exploitation, patches, or technical details.

    23521768428.3K
    5.1K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Claude + Humans vs nginx: CVE-2026-27654 https://blog.calif.io/p/claude-humans-vs-nginx-cve-2026-27654

    Post summary

    The tweet simply links to a blog post about CVE-2026-27654 affecting nginx, without providing further technical details or exploits.

    114077407.0K
    157.5K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Claude + Humans vs nginx: CVE-2026-27654 https://blog.calif.io/p/claude-humans-vs-nginx-cve-2026-27654

    Post summary

    The text announces the discovery of a new CVE (CVE-2026-27654) related to nginx, with no additional technical or exploit details provided.

    01032794
    33.3K followersView on X
  • dbugs@ptdbugs
    Disclosure

    NGINX ngx_http_dav_module vulnerability CVE: CVE-2026-27654 PT-Identifier: PT-2026-27430 Vendor: F5 Product: NGINX Open Source CVSS: 8.2 Credits: F5 acknowledges http://Calif.io in collaboration with Claude and Anthropic Research for bringing this issue to our attention and following the highest standards of coordinated disclosure. Description: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27654 • https://my.f5.com/manage/s/article/K000160382 #dbugs_vuln

    Post summary

    CVE‑2026‑27654 is a buffer‑overflow vulnerability in NGINX’s DAV module that can terminate or alter files outside the document root, with an 8.2 CVSS score—technical details are provided, but no PoC, exploit code, or active exploitation evidence is present.

    00032189
    746 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23877/

    Post summary

    The update release note announces version 1.28.3‑1.el9 of the kusanagi‑nginx128 module, addressing several CVEs, thereby serving as a patch advisory.

    0202085
    200 followersView on X
  • dbugs@ptdbugs
    Exploit

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-27654 Vendor: F5 Product: NGINX Open Source Description: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Link: https://github.com/JohannesLks/CVE-2026-27654 #dbugs_vuln

    Post summary

    A functional exploit/PoC for CVE-2026-27654 is available on GitHub, detailing a buffer overflow in the DAV module; no mention of active exploitation or patches.

    00002352
    788 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🌐 CVE-2026-27654 (NGINX Open Source/Plus ngx_http_dav_module): 8.8 HIGH heap buffer overflow via crafted DAV requests. Patch: NGINX update https://nginx.org/en/security_advisories.html https://nvd.nist.gov/vuln/detail/CVE-2026-27654 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27654

    Post summary

    The post announces a high‑severity heap buffer overflow in NGINX’s DAV module and directs users to apply the vendor’s patch.

    1001043
    492 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23884/

    Post summary

    KUSANAGI 9's nginx128 module was updated to version 1.28.3-1, with the update containing patches for six listed CVEs and a release page link for more information.

    0101091
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23870/

    Post summary

    The post announces a module update that includes patches for several CVEs, providing no further technical detail or exploitation information.

    0101086
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23864/

    Post summary

    The post announces an update to the kusanagi-nginx129 module (v1.29.7-1.el9) that patches multiple CVEs.

    01010100
    200 followersView on X
  • Nexusguard@Nexusguard
    Disclosure

    🚨URGENT: NGINX Rift Vulnerability Now Live CVE-2026-42945 (NGINX Rift) and CVE-2026-27654 are actively raising alarms across the industry. Attackers can trigger DoS — or worse, potential RCE — by exploiting specific rewrite rules, unnamed regex captures, or WebDAV + alias configurations in exposed NGINX instances. Don’t assume you’re safe just because you run NGINX. Full technical breakdown + immediate actions in our new blog 🔗 https://www.nexusguard.com/blog/recent-nginx-vulnerabilities-what-customers-need-to-know-about-nginx-rift-and-related-issues Act now before scans turn into exploits. #NGINXRift #Cybersecurity #Vulnerability #WebSecurity

    Post summary

    The post announces the NGINX Rift vulnerabilities with technical details and a warning to act, without providing a PoC, exploit code, or patch information.

    0000166
    2.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27654 Buffer Overflow Vulnerability in NGINX DAV Module via MOV... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27654 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-27654, describing a buffer overflow in the NGINX DAV module, and provides a link to detailed vulnerability information, but does not mention active exploitation, a PoC, or a patch.

    0000145
    4.0K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability (CVE-2026-27654) https://www.systemtek.co.uk/2026/08/nginx-http-dav-module-alias-directive-integer-underflow-remote-code-execution-vulnerability-cve-2026-27654/ via @SystemTek_UK

    Post summary

    The post announces the discovery of an integer underflow flaw in NGINX's HTTP Dav module that enables remote code execution, with further details linked in an article.

    0000074
    1.8K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-27654 | F5 NGINX Open Source/NGINX Plus DAV Module ngx_http_dav_module heap-based overflow (K000160382 / Nessus ID 305582) https://ift.tt/Doubx1H A vulnerability identified as critical has been detected in F5 NGINX Open Source and NGINX Plus. Affected by this vulnerab…

    Post summary

    A critical heap-based overflow vulnerability has been identified in the F5 NGINX Open Source/NGINX Plus DAV module. No PoC, exploit code, or patch has been disclosed in the text.

    0000052
    974 followersView on X
  • Michael Martino@battista212
    Disclosure

    Claude AI agent just discovered NGINX RCE (CVE-2026-27654), patched end of March. AI-assisted vulnerability research is now production-ready and finding critical bugs faster than human researchers.

    Post summary

    Claude AI agent uncovered a new NGINX remote code execution vulnerability (CVE‑2026‑27654), which has already been patched by the end of March, underscoring the effectiveness of AI-driven vulnerability research.

    0000072
    193 followersView on X
  • Secwiser - Cyber Security Insights@Secwiserapp
    Patch

    Nginx WebDAV Overflow: Patch CVE-2026-27654 AI-assisted discovery flags a heap overflow in nginx WebDAV handling (CVE-2026-27654) triggered by a short Destination header under an alias/dav combo. Humans refined PoCs, reduced preconditions, and validated attack paths. Coordinated disclosure with F5; patch 2026-03-24; writeup published. Read more: https://blog.calif.io/p/claude-humans-vs-nginx-cve-2026-27654 Discover the app: https://www.secwiser.com/app #CyberSecurity #WebSecurity #Vulnerability #CVE2026-27654 #CloudSecurity #DevOps #Kubernetes #AWS #Azure #Secwiser #InfrastructureSecurity

    Post summary

    The post announces a heap‑overflow vulnerability in nginx WebDAV, details PoC refinement, and reports a coordinated patch scheduled for March 2026.

    0000041
    20 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    AI-assisted research uncovered nginx CVE-2026-27654, a heap overflow in WebDAV COPY/MOVE handling that allows path traversal and arbitrary file read/write, with exploit reproduction possible immediately after patch release. https://blog.calif.io/p/claude-humans-vs-nginx-cve-2026-27654

    Post summary

    Researchers uncovered a heap overflow in nginx’s WebDAV COPY/MOVE handling (CVE‑2026‑27654) that permits path traversal and arbitrary file read/write, with proof‑of‑concept exploitation reproducible immediately after the patch release.

    00000106
    2.0K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos NGINX ❗ CVE-2026-32647 ❗ CVE-2026-27654 ❗ CVE-2026-27651 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-nginx/ https://t.co/o4ory9vuST

    Post summary

    The post lists three CVEs affecting NGINX products but provides no details on exploitation, patch status, or technical specifics.

    00000151
    6.6K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    nginxに深刻なバッファオーバーフロー 脆弱性(CVE-2026-27654)など https://rocket-boys.co.jp/security-measures-lab/nginx-cve-2026-27654-critical-buffer-overflows/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The tweet highlights a severe buffer overflow vulnerability in nginx (CVE-2026-27654) and links to a security lab article, but does not provide proof of exploitation or patch details.

    00000129
    364 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.3-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.3-1 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651,... https://kusanagi.tokyo/en/releases/23885/

    Post summary

    The update announces that Kusanagi Nginx 128 1.28.3-1 includes patches for CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, and CVE-2026-27651.

    0000054
    200 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_open_source---
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr35--
Appf5nginx_plusr35--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--

Explore more