CVE-2026-27784Patch(f5 / nginx_open_source)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 nginx_open_source systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_open_source

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 8 mentions (2026-03-26); latest day: 1
  • 12 total mentions across 3 days

Affected systems

Vendors
Products
nginx_open_source

Deep dive

Activity timeline12 mentions / 3d
02468Mentions · 2026-03-24: 3Mentions · 2026-03-26: 8Mentions · 2026-05-20: 1Patch / Workaround · 2026-03-26: 7Technical Details · 2026-03-24: 3Technical Details · 2026-03-26: 1Technical Details · 2026-05-20: 103-2403-2605-20
Signal classification3 categories
Patch
866.7%
Disclosure
325.0%
General
18.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure2General1
2026-03-268
Patch8
2026-05-201
Disclosure1
Full discourse12 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23877/

    Post summary

    The release notes announce a module update that includes patches for several CVEs, indicating a vendor-provided fix.

    0202085
    200 followersView on X
  • dbugs@ptdbugs
    Disclosure

    NGINX ngx_http_mp4_module vulnerability CVE: CVE-2026-27784 PT-Identifier: PT-2026-27431 Vendor: F5 Product: NGINX Open Source CVSS: 7.8 Credits: F5 acknowledges Prabhav Srinath (sprabhav7) for bringing this issue to our attention and following the highest standards of coordinated disclosure. Description: The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27784 • https://my.f5.com/manage/s/article/K000160364 #dbugs_vuln

    Post summary

    This entry announces the discovery of a CVE affecting NGINX’s 32‑bit mp4 module, providing key technical details but no PoC, exploit code, or patch information.

    00022155
    746 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23884/

    Post summary

    The update announcement confirms that version 1.28.3-1 of the KUSANAGI nginx128 module includes patches for several CVEs, but provides no PoC, exploit, or technical details.

    0101091
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23870/

    Post summary

    The update announces patches for several CVEs, indicating a patch release.

    0101086
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23864/

    Post summary

    KUSANAGI 9 nginx129 module updated to 1.29.7-1.el9, patching a set of CVEs.

    01010100
    200 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27784 NGINX Open Source 32-bit ngx_http_mp4_module Memory Corruption Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27784

    Post summary

    The post announces CVE‑2026‑27784, describing it as a memory‑corruption flaw in NGINX’s ngx_http_mp4_module and links to a detail page, but offers no PoC, exploit, patch, or activity information.

    0000140
    4.0K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-27784 | F5 NGINX Open Source ngx_http_mp4_module integer overflow (K000160364 / Nessus ID 305646) https://ift.tt/f2nBFHR A vulnerability marked as critical has been reported in F5 NGINX Open Source. This affects the function ngx_http_mp4_module. This manipulation caus…

    Post summary

    The text announces a critical integer overflow vulnerability (CVE‑2026‑27784) affecting F5 NGINX Open Source's ngx_http_mp4_module, but does not provide a PoC, exploit, or patch information.

    0000052
    974 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.3-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.3-1 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651,... https://kusanagi.tokyo/en/releases/23885/

    Post summary

    KUSANAGI released nginx128 version 1.28.3-1 patching multiple CVEs (CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651), with no PoC or exploitation details provided.

    0000054
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.3-1.el9 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.3-1.el9 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647,... https://kusanagi.tokyo/en/releases/23878/

    Post summary

    This release notes the update to kusanagi‑nginx128 version 1.28.3‑1.el9, indicating that the update aims to address CVE‑2026‑27654, CVE‑2026‑27784, and CVE‑2026‑32647, but provides no further technical detail or evidence of exploitation.

    0000057
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 Module Update 1.29.7-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx129 1.29.7-1 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651,... https://kusanagi.tokyo/en/releases/23871/

    Post summary

    KUSANAGI released a module update that patches several listed CVEs; the post contains no PoC, exploit, or technical details about the vulnerabilities.

    0000054
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 Module Update 1.29.7-1.el9 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx129 1.29.7-1.el9 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647,... https://kusanagi.tokyo/en/releases/23865/

    Post summary

    This release notes that the Kusanagi nginx module has been updated to patch CVE‑2026‑27654, CVE‑2026‑27784, CVE‑2026‑32647, providing a library update that addresses these vulnerabilities.

    0000060
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27784 The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX w… https://www.cve.org/CVERecord?id=CVE-2026-27784

    Post summary

    The post announces a new vulnerability (CVE-2026-27784) affecting the 32‑bit NGINX ngx_http_mp4_module, noting potential over‑read or over‑write weaknesses, but does not provide PoC, exploit code, or patch information.

    0000095
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_open_source---

Explore more