ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability
Published Aug 13, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NGINX. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-27654.
Affected Software
1 affected component
nginx
Event History
Aug 13, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-578?
ZDI-26-578 has a CVSS rating of 8.1, indicating a high severity level.
2
How do I fix ZDI-26-578?
To mitigate ZDI-26-578, update NGINX to the latest version that addresses this vulnerability.
3
What types of attacks can leverage ZDI-26-578?
ZDI-26-578 can be exploited by remote attackers to execute arbitrary code without requiring authentication.
4
Which software is affected by ZDI-26-578?
NGINX is the software affected by the ZDI-26-578 vulnerability.
5
What is the nature of the ZDI-26-578 vulnerability?
ZDI-26-578 is an integer underflow vulnerability in the NGINX HTTP Dav Module.