NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 8.5 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginx-mod-develUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-mod-mailUpgrade nginx-coreUpgrade nginxUpgrade nginx-mod-http-perlUpgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginx-mod-http-image-filter | Apr 13, 2026 | Apr 7, 2026 |
| Alpine Linux | — | Upgrade nginx | Mar 27, 2026 | Mar 24, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-all-modulesUpgrade nginx-mod-http-geoipUpgrade nginxUpgrade nginx-mod-http-perlUpgrade nginx-mod-develUpgrade nginx-mod-mailUpgrade nginx-mod-http-image-filterUpgrade nginx-coreUpgrade nginx-mod-streamUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-filesystem | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-mod-develUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-streamUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-coreUpgrade nginxUpgrade nginx-debugsourceUpgrade nginx-filesystemUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mail | Apr 14, 2026 | Mar 24, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.29.7Upgrade to nginx version 1.28.3 | Mar 27, 2026 | Mar 24, 2026 |
| Oracle_linux | — | Upgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-filesystemUpgrade nginx-coreUpgrade nginx-mod-develUpgrade nginx-mod-http-image-filterUpgrade nginxUpgrade nginx-mod-http-perl | Apr 22, 2026 | Mar 24, 2026 |
| Redhat_linux | — | Upgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-streamUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginx-coreUpgrade nginx-filesystemUpgrade nginx-all-modulesUpgrade nginx-debugsourceUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-develUpgrade nginx-mod-mailUpgrade nginx-debuginfo | Apr 9, 2026 | Mar 24, 2026 |
| Rocky_linux | — | Upgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debugsourceUpgrade nginxUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-mailUpgrade nginx-coreUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-core-debuginfoUpgrade nginx-mod-devel | Apr 10, 2026 | Apr 8, 2026 |
| Ubuntu | — | Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade nginx-lightUpgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade nginx-coreUpgrade nginxUpgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade nginx-fullUpgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade nginx-extrasUpgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro) | Apr 28, 2026 | Apr 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub