High [CVE-2026-27654] NGINX ngx_http_dav_module vulnerability
This high-severity F5 advisory covers CVE-2026-27654 affecting NGINX Open Source, NGINX Plus.
Android app · Google Play
Monitor future F5 CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root.
This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- NGINX Open Source 1.29.0 before 1.29.7
- NGINX Open Source 0.5.13 before 1.28.3
- NGINX Plus R36 before R36 P3
- NGINX Plus R35 before R35 P2
- NGINX Plus R34
- NGINX Plus R33
- NGINX Plus R32 before R32 P5
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
- 1.29.7
- 1.28.3
- R36 P3
- R35 P2
- R32 P5
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Mitigation
Upgrade to a fixed release: 1.29.7, 1.28.3, R36 P3, R35 P2, R32 P5. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.