NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 8.8 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-all-modulesUpgrade nginxUpgrade nginx-mod-develUpgrade nginx-mod-streamUpgrade nginx-coreUpgrade nginx-mod-http-xslt-filterUpgrade nginx-filesystemUpgrade nginx-mod-mail | Apr 13, 2026 | Apr 7, 2026 |
| Alpine Linux | — | Upgrade nginx | Mar 27, 2026 | Mar 24, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginxUpgrade nginx-mod-develUpgrade nginx-mod-mailUpgrade nginx-mod-http-geoipUpgrade nginx-all-modulesUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-coreUpgrade nginx-filesystemUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filter | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-core-debuginfoUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-coreUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-develUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-streamUpgrade nginx-mod-mail-debuginfoUpgrade nginx-filesystemUpgrade nginx-debugsource | Apr 14, 2026 | Mar 24, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.28.3Upgrade to nginx version 1.29.7 | Mar 27, 2026 | Mar 24, 2026 |
| Oracle_linux | — | Upgrade nginxUpgrade nginx-coreUpgrade nginx-mod-http-perlUpgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginx-filesystemUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-devel | Apr 22, 2026 | Mar 24, 2026 |
| Redhat_linux | — | Upgrade nginx-coreUpgrade nginx-all-modulesUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-debugsourceUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-mailUpgrade nginx-filesystemUpgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-core-debuginfoUpgrade nginx-mod-devel | Apr 9, 2026 | Mar 24, 2026 |
| Rocky_linux | — | Upgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-coreUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-core-debuginfoUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-develUpgrade nginx-debugsourceUpgrade nginx-mod-mailUpgrade nginx-mod-http-perl-debuginfo | Apr 10, 2026 | Apr 8, 2026 |
| Ubuntu | — | Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade nginx-coreUpgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade nginx-fullUpgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade nginx-extrasUpgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade nginxUpgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade nginx (Ubuntu Pro) | Apr 28, 2026 | Apr 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub