ZeroHour
Product

NGINX

0 mentions in 7 days · 0 in 30 days · 1 total · first seen · last

Timeline

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

An unauthenticated integer underflow (CVE-2026-27654, CVSS 8.1) in NGINX's HTTP Dav module alias directive enables remote code execution.

ZDI advisory ZDI-26-578 describes an integer underflow in the alias directive of the NGINX HTTP Dav module that allows remote attackers to execute arbitrary code. Authentication is not required to exploit the vulnerability. ZDI rated the issue 8.1 on CVSS and assigned CVE-2026-27654.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-27654

Related CVEs

  • Buffer Overflow in NGINX ngx_http_dav_module via DAV MOVE/COPY with Alias
    NGINX Open Source and NGINX Plus contain a buffer overflow (CWE-122/CWE-120) in the ngx_http_dav_module that can be triggered by an unauthenticated remote attacker. Exploitation requires a configuration that enables the DAV module's MOVE or COPY methods together with a prefix (non-regular-expression) location and an alias directive, after which crafted MOVE/COPY requests can overflow a buffer in the worker process. A successful attack can terminate the NGINX worker process (denial of service, high availability impact) or modify source or destination file names outside the document root, with integrity impact limited because the worker process runs with low privileges. Only deployments using that specific DAV configuration are affected, and versions that have reached End of Technical Support were not evaluated. No public proof-of-concept or CISA KEV listing exists yet, but EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile), and the ZDI advisory (ZDI-26-578) describes the underlying integer underflow as potentially leading to remote code execution.
    · f5 nginx open source · f5 nginx pluslarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.