CVE-2026-32647Patch(f5 / nginx_open_source)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 nginx_open_source systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.8/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_open_source
  • nginx_plus

Threat summary

  • Patch or workaround signal is available
  • 18 mentions across 8 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 9 mentions (2026-03-26); latest day: 1
  • 18 total mentions across 8 days

Affected systems

Vendors
Products
nginx_open_sourcenginx_plus

5 versions affected across 2 products

Deep dive

Activity timeline18 mentions / 8d
02579Mentions · 2026-03-24: 3Mentions · 2026-03-25: 1Mentions · 2026-03-26: 9Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-04-01: 1Mentions · 2026-05-20: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 9Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-01: 1Technical Details · 2026-05-20: 103-2403-2503-2603-2703-2803-3004-0105-20
Signal classification3 categories
Patch
1055.6%
Disclosure
633.3%
General
211.1%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure3
2026-03-251
Patch1
2026-03-269
Patch9
2026-03-271
Disclosure1
2026-03-281
Disclosure1
2026-03-301
General1
2026-04-011
Disclosure1
2026-05-201
General1
Full discourse18 posts
  • Hunt.io@Huntio
    Disclosure

    ⚠️ NGINX MP4 Module Flaw Enables DoS and Potential Code Execution https://gbhackers.com/f5-nginx-plus-open-source-flaw/ A high-severity flaw (CVE-2026-32647) in NGINX’s MP4 module allows attackers to trigger DoS or potentially achieve code execution using crafted video files. The issue stems from an out-of-bounds read and affects systems where the mp4 module is explicitly enabled. Exploitation can crash worker processes and disrupt traffic. Fixes are available in recent NGINX releases. If you can’t patch right away, consider disabling the mp4 directive or limiting who can upload media files. #CyberSecurity #NGINX #ThreatIntelligence

    Post summary

    The post discloses CVE-2026-32647, an MP4 module flaw in NGINX that can lead to DoS and potential code execution, and urges users to apply patches or disable the vulnerable module.

    1401221.2K
    5.4K followersView on X
  • dbugs@ptdbugs
    Disclosure

    NGINX ngx_http_mp4_module vulnerability CVE: CVE-2026-32647 PT-Identifier: PT-2026-27436 Vendor: F5 Product: NGINX Open Source CVSS: 7.8 Credits: F5 acknowledges Xint Code and Pavel Kohout (Aisle Research) for bringing this issue to our attention and following the highest standards of coordinated disclosure. Description: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted mp4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-32647 • https://my.f5.com/manage/s/article/K000160366 #dbugs_vuln

    Post summary

    This text announces the discovery of CVE-2026-32647, describing its technical impact and including CVSS scoring, but provides no PoC, exploit code, or evidence of active exploitation.

    040105742
    746 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23877/

    Post summary

    The post announces an update to the Kusanagi Nginx module that addresses multiple CVEs, serving as a patch release.

    0202085
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23884/

    Post summary

    This release notes update Kusanagi‑nginx128 to version 1.28.3‑1, addressing a set of listed CVEs with a patch.

    0101091
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23870/

    Post summary

    The Kusani-nginx129 module update v1.29.7-1 includes patches for several CVE-2026 vulnerabilities and does not mention any PoC, exploit, or active exploitation.

    0101086
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23864/

    Post summary

    Kusanagi 9’s nginx129 module update (1.29.7-1.el9) addresses a set of CVEs, effectively patching the identified vulnerabilities.

    01010100
    200 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    F5 NGINX Plus/Open Source の脆弱性 CVE-2026-32647 が FIX:MP4 ファイルを介した任意のコード実行 https://iototsecnews.jp/2026/03/25/f5-nginx-plus-opensource-flaw-lets-attackers-execute-code-via-mp4-file/ この脆弱性 CVE-2026-32647 は、NGINX で MP4 ファイルを扱うモジュールがデータを読み書きする際、あらかじめ用意されたメモリの範囲を超えて処理を行ってしまうことが原因で発生します。本来はアクセス不可のメモリ領域での操作を許すため、システムの動作が不安定になり、サービス停止や不正な外部コマンドの実行などの恐れが生じます。この脆弱性が影響を及ぼす範囲は、NGINX Plus や NGINX Open Source の、mp4 ディレクティブが有効化されている環境となります。ご利用のチームは、ご注意ください。 #CVE202632647 #F5 #NGINXPlus #Vulnerability

    Post summary

    The article discloses CVE-2026-32647 in NGINX, detailing a memory‑overflow in MP4 handling that could allow arbitrary code execution, but provides no PoC, exploit code, or evidence of active attacks.

    01000173
    481 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32647 NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to … https://www.cve.org/CVERecord?id=CVE-2026-32647

    Post summary

    The post announces CVE‑2026‑32647, detailing an over‑read/over‑write flaw in NGINX’s ngx_http_mp4_module, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000196
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32647 Buffer Overflow Vulnerability in NGINX MP4 Module via Malformed MP4 File https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32647

    Post summary

    The post merely announces a buffer overflow vulnerability in the NGINX MP4 module triggered by a malformed MP4 file, without providing any PoC, exploit code, active exploitation evidence, or patch details.

    0000152
    4.0K followersView on X
  • Israel@f1tym1
    General

    CVE-2026-32647 | F5 NGINX Open Source/NGINX Plus ngx_http_mp4_module out-of-bounds (K000160366 / Nessus ID 305582) https://ift.tt/olVfBNP A vulnerability labeled as problematic has been found in F5 NGINX Open Source and NGINX Plus. Affected by this issue is the function ngx_ht…

    Post summary

    CVE-2026-32647 is an out‑of‑bounds vulnerability affecting F5 NGINX Open Source and NGINX Plus, but the provided text offers only basic technical details and no evidence of exploitation, patches, or PoC.

    0000048
    974 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos NGINX ❗ CVE-2026-32647 ❗ CVE-2026-27654 ❗ CVE-2026-27651 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-nginx/ https://t.co/o4ory9vuST

    Post summary

    A short Spanish tweet lists several CVE identifiers for NGINX products and provides links for further information, but offers no additional technical context or evidence of exploitation.

    00000151
    6.6K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @Huntio Upload a crafted MP4 and crash the web server - CVE-2026-32647 turns NGINX's media handling into an attack vector. Anyone serving video content with the mp4 module enabled just got a new reason to audit their config. https://vulntracker.io

    Post summary

    The tweet warns that CVE‑2026‑32647 causes NGINX’s MP4 module to crash on crafted MP4 uploads, urging users to audit their configurations.

    0000034
    495 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Alert: High-severity vulnerability CVE-2026-32647 in NGINX allows code execution via malicious MP4 files. Update to patched versions immediately. Link: https://thedailytechfeed.com/critical-nginx-flaw-allows-code-execution-via-malicious-mp4-files-update-urgently/ #Security #NGINX #Vulnerability #Patch #Update #Malware #Exploit #Threat #Mitigation #Risk #CVE #Network #Software #System #Protection #Bug #Alert #Flaw #IT #Safety

    Post summary

    High‑severity CVE‑2026‑32647 in NGINX allows code execution through malicious MP4 files; patched (upgraded) versions are immediately advised to mitigate the risk.

    0000016
    270 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.3-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.3-1 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651,... https://kusanagi.tokyo/en/releases/23885/

    Post summary

    Kusanagi released module update 1.28.3-1, addressing multiple CVEs (CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651) by providing a patch.

    0000054
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.3-1.el9 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.3-1.el9 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647,... https://kusanagi.tokyo/en/releases/23878/

    Post summary

    The Kusanagi-nginx128 module update addresses CVE‑2026‑27654, CVE‑2026‑27784, CVE‑2026‑32647 by patching them, with no PoC or exploit details provided.

    0000057
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 Module Update 1.29.7-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx129 1.29.7-1 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651,... https://kusanagi.tokyo/en/releases/23871/

    Post summary

    The text announces a KUSANAGI module update that patches several CVEs, providing no exploit or technical detail beyond the CVE identifiers.

    0000054
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 Module Update 1.29.7-1.el9 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx129 1.29.7-1.el9 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647,... https://kusanagi.tokyo/en/releases/23865/

    Post summary

    The release updates Kusanagi Nginx modules to patch vulnerabilities identified as CVE-2026-27654, CVE-2026-27784, and CVE-2026-32647, with no PoC, exploit code, or active exploitation reported.

    0000060
    200 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 #CVE-2026-32647: Critical NGINX MP4 Module Flaw Exposes Servers to Remote Code Execution—Patch Now! + Video https://undercodetesting.com/cve-2026-32647-critical-nginx-mp4-module-flaw-exposes-servers-to-remote-code-execution-patch-now-video/ Educational Purposes!

    Post summary

    The post announces CVE‑2026‑32647, highlights its RCE risk, and urges applying the patch, but provides no PoC or evidence of active attacks.

    0000031
    427 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_open_source---
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr35--
Appf5nginx_plusr35--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--

Explore more