NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 8.5 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-coreUpgrade nginxUpgrade nginx-mod-http-perlUpgrade nginx-filesystemUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-mod-devel | Apr 13, 2026 | Apr 7, 2026 |
| Alpine Linux | — | Upgrade nginx | Mar 27, 2026 | Mar 24, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-filesystemUpgrade nginx-debuginfoUpgrade nginx-mod-develUpgrade nginx-mod-http-perlUpgrade nginx-coreUpgrade nginx-all-modulesUpgrade nginx-mod-http-geoipUpgrade nginxUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mail | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-mod-develUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-streamUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-debugsourceUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-filesystemUpgrade nginx-coreUpgrade nginx-mod-mailUpgrade nginx-mod-http-perlUpgrade nginxUpgrade nginx-mod-http-image-filterUpgrade nginx-all-modules | Apr 14, 2026 | Mar 24, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.28.3Upgrade to nginx version 1.29.7 | Mar 27, 2026 | Mar 24, 2026 |
| Oracle_linux | — | Upgrade nginxUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-develUpgrade nginx-mod-mailUpgrade nginx-filesystemUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-core | Apr 22, 2026 | Mar 24, 2026 |
| Redhat_linux | — | Upgrade nginx-mod-mailUpgrade nginx-debuginfoUpgrade nginx-filesystemUpgrade nginx-debugsourceUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-develUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-mod-http-perlUpgrade nginx-core-debuginfoUpgrade nginx-coreUpgrade nginx-mod-stream-debuginfo | Apr 9, 2026 | Mar 24, 2026 |
| Rocky_linux | — | Upgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-mailUpgrade nginx-debugsourceUpgrade nginx-debuginfoUpgrade nginx-coreUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-streamUpgrade nginx-mod-develUpgrade nginx-mod-http-perlUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-image-filter | Apr 10, 2026 | Apr 8, 2026 |
| Ubuntu | — | Upgrade nginx-fullUpgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade nginx-extrasUpgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade nginx-lightUpgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade nginxUpgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade nginx-coreUpgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro) | Apr 28, 2026 | Apr 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub