CVE-2026-27654: NGINX ngx_http_dav_module vulnerability

Published Mar 24, 2026
·
Updated

Last updated 6 June 2026

Other sources

NGINX Open Source and NGINX Plus have a vulnerability in the ngxhttpdavmodule module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system.

F5

Affected Software

27 affected componentsFixes available
Nginx NGINX Open Source
Nginx NGINX Plus
F5 NGINX Plus=32
36
F5 NGINX Open Source>=1.0.0<=1.29.6
1.29.71.28.3
F5 NGINX Open Source>=0.5.13<=0.9.7
F5 NGINX Plus=r32-p1
F5 NGINX Plus=r32-p2
F5 NGINX Plus=r32-p3
F5 NGINX Plus=r32-p4
F5 NGINX Plus=r33
F5 NGINX Plus=r33-p1
F5 NGINX Plus=r33-p2
F5 NGINX Plus=r33-p3
F5 NGINX Plus=r34
F5 NGINX Plus=r34-p1
F5 NGINX Plus=r34-p2
F5 NGINX Plus=r35
F5 NGINX Plus=r35-p1
F5 NGINX Plus=r36
F5 NGINX Plus=r36-p1
F5 NGINX Plus=r36-p2
F5 NGINX Open Source>=0.5.13<=0.9.7
F5 NGINX Open Source>=1.0.0<1.28.3
F5 NGINX Open Source>=1.29.0<1.29.7
Microsoft azl3 nginx 1.28.2-1
Microsoft cbl2 nginx 1.22.1-15
debian/nginx<=1.18.0-6.1+deb11u3
1.18.0-6.1+deb11u61.22.1-9+deb12u61.22.1-9+deb12u71.26.3-3+deb13u41.26.3-3+deb13u51.30.1-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 36
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.29.71.28.3
  3. Upgrade

    Upgrade debian/nginx to a version that resolves this vulnerability.

    Fixed in 1.18.0-6.1+deb11u6Fixed in 1.22.1-9+deb12u6Fixed in 1.22.1-9+deb12u7Fixed in 1.26.3-3+deb13u4Fixed in 1.26.3-3+deb13u5Fixed in 1.30.1-3
  4. Compensating control

    Review NGINX configuration to identify usage of ngx_http_dav_module MOVE or COPY methods with prefix location (nonregular expression location configuration) and alias directives; remove/avoid these DAV MOVE/COPY configurations so the vulnerable code path is not reachable.

Event History

Mar 24, 2026
Advisory Published
via F5·01:25 PM
Data Sourced
via F5·01:25 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·03:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 27, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Jun 3, 2026
Data Sourced
via Launchpad·01:43 PM
Description
Data Sourced
via Debian·01:43 PM
DescriptionAffected Software
Jun 6, 2026
Data Sourced
via Ubuntu·01:44 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27654?

CVE-2026-27654 is classified as a high severity vulnerability that can lead to a buffer overflow in NGINX.

2

How do I fix CVE-2026-27654?

To fix CVE-2026-27654, update your NGINX Open Source to version 1.29.71.28.3 or NGINX Plus to version 36.

3

Which versions of NGINX are affected by CVE-2026-27654?

CVE-2026-27654 affects NGINX Open Source versions prior to 1.29.71.28.3 and NGINX Plus prior to version 36.

4

What type of attack can CVE-2026-27654 facilitate?

CVE-2026-27654 can facilitate a denial-of-service attack by terminating the NGINX worker process due to a buffer overflow.

5

Is there a workaround for CVE-2026-27654?

There is no known workaround for CVE-2026-27654, so upgrading to the patched versions is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203