Bug 2450785 (CVE-2026-27784) - CVE-2026-27784 NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file
Summary: CVE-2026-27784 NGINX: NGINX: Denial of Service due to memory corruption via c...
Keywords:
Status: NEW
Alias: CVE-2026-27784
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2450840
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-24 15:02 UTC by OSIDB Bzimport
Modified: 2026-03-24 20:47 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-24 15:02:30 UTC
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. 


Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


Note You need to log in before you can comment on or make changes to this bug.