Skip to content
VulniPulse
High8.2F5

High [CVE-2026-27654] NGINX ngx_http_dav_module vulnerability

This high-severity F5 advisory covers CVE-2026-27654 affecting NGINX Open Source, NGINX Plus.

CVE-2026-27654 Published Mar 24, 2026Updated by vendor Jul 15, 2026
Affected products & platforms
F5NGINX
Open vendor advisory

Android app · Google Play

Monitor future F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root.

This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • NGINX Open Source 1.29.0 before 1.29.7
  • NGINX Open Source 0.5.13 before 1.28.3
  • NGINX Plus R36 before R36 P3
  • NGINX Plus R35 before R35 P2
  • NGINX Plus R34
  • NGINX Plus R33
  • NGINX Plus R32 before R32 P5

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Fixed versions
  • 1.29.7
  • 1.28.3
  • R36 P3
  • R35 P2
  • R32 P5

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Mitigation

Upgrade to a fixed release: 1.29.7, 1.28.3, R36 P3, R35 P2, R32 P5. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.