ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

mediumVulnerabilityimportance 30CVE-2026-27654
AI summary · glm-5.3-flash

An unauthenticated integer underflow (CVE-2026-27654, CVSS 8.1) in NGINX's HTTP Dav module alias directive enables remote code execution.

ZDI advisory ZDI-26-578 describes an integer underflow in the alias directive of the NGINX HTTP Dav module that allows remote attackers to execute arbitrary code. Authentication is not required to exploit the vulnerability. ZDI rated the issue 8.1 on CVSS and assigned CVE-2026-27654.

  • Unauthenticated remote code execution in the NGINX HTTP Dav module.
  • Affects the alias directive via an integer underflow.
  • CVSS 8.1; tracked as CVE-2026-27654 under ZDI-26-578.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-27654
Buffer Overflow in NGINX ngx_http_dav_module via DAV MOVE/COPY with Alias

NGINX Open Source and NGINX Plus contain a buffer overflow (CWE-122/CWE-120) in the ngx_http_dav_module that can be triggered by an unauthenticated remote attacker. Exploitation requires a configuration that enables the DAV module's MOVE or COPY methods together with a prefix (non-regular-expression) location and an alias directive, after which crafted MOVE/COPY requests can overflow a buffer in the worker process. A successful attack can terminate the NGINX worker process (denial of service, high availability impact) or modify source or destination file names outside the document root, with integrity impact limited because the worker process runs with low privileges. Only deployments using that specific DAV configuration are affected, and versions that have reached End of Technical Support were not evaluated. No public proof-of-concept or CISA KEV listing exists yet, but EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile), and the ZDI advisory (ZDI-26-578) describes the underlying integer underflow as potentially leading to remote code execution.

Do: Audit nginx.conf for dav_methods directives enabling MOVE or COPY inside prefix (non-regex) locations that use alias directives, and if present upgrade NGINX Open Source or NGINX Plus to a fixed release per the F5 SIRT advisory, since no fixed version numbers are provided in this data. As interim mitigation, disable MOVE/COPY DAV methods, remove the alias directive from the affected prefix location, or restrict DAV endpoints to trusted networks. Because End-of-Technical-Support versions were not evaluated, deployments on older releases should move to a supported version before patching.

8.825%
  • f5 nginx open source
  • f5 nginx plus
largetens of thousands of internet-exposed NGINX servers with the vulnerable DAV configuration
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NGINX. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-27654.

This source does not provide full text. Read it at zerodayinitiative.com.