Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-27654

CVE-2026-27654: 2 tracked advisory records across F5, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

F5

1 advisory
  • Advisory severityHigh8.2

    High [CVE-2026-27654] NGINX ngx_http_dav_module vulnerability

    CVE-2026-27654Source published Source updated

    NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Affected products in this advisory
    • NGINX Open Source
    • NGINX Plus
    Source-reported affected versions
    • NGINX Open Source 1.29.0 before 1.29.7
    • NGINX Open Source 0.5.13 before 1.28.3
    • NGINX Plus R36 before R36 P3
    • NGINX Plus R35 before R35 P2

    3 more entries in the full advisory.

    Source-reported fixed versions
    • 1.29.7
    • 1.28.3
    • R36 P3
    • R35 P2

    1 more entries in the full advisory.

    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Red Hat

1 advisory
  • Advisory severityHigh8.2

    High [CVE-2026-27654] Denial of Service or file modification via buffer overflow in ngx_http_dav_module

    CVE-2026-27654Source published

    Denial of Service or file modification via buffer overflow in ngx_http_dav_module. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`).

    Affected products in this advisory
    • NGINX Open Source
    • NGINX Plus
    • Red Hat Enterprise Linux 10.0 Extended Update Support
    • Red Hat Enterprise Linux 8

    6 more entries in the full advisory.

    Source-reported affected versions
    • nginx-main-1.30.0-1.hum1
    • nginx-2:1.26.3-1.el10_0.8
    • nginx-2:1.20.1-24.el9_7.2
    • nginx:1.26-9060020260504154614.9

    8 more entries in the full advisory.

    Source-reported fixed versions
    • RHSA-2026:6906
    Mitigation guidance
    • Update the affected package(s) to the fixed version shipped in RHSA-2026:6906 (`sudo dnf update` / `yum update`).

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery