Executive brief
NGINX Open Source and NGINX Plus are widely used web servers and load balancers. A vulnerability in the module responsible for WebDAV file management could allow a remote attacker to crash the server's worker processes or potentially modify file names outside of the intended directory. While the impact is somewhat limited by the low privileges of the NGINX process, an exploit could still lead to service outages or unauthorized file manipulation.
Technical details
A buffer overflow vulnerability exists in the ngx_http_dav_module of NGINX Open Source and NGINX Plus. The flaw is triggered when the configuration utilizes the DAV module's MOVE or COPY methods in conjunction with prefix locations (non-regular expression) and the 'alias' directive. A remote, unauthenticated attacker can exploit this to cause a heap-based buffer overflow in the NGINX worker process. Successful exploitation can result in the termination of the worker process (Denial of Service) or the modification of source/destination file names outside the configured document root. Integrity impact is mitigated by the fact that NGINX worker processes typically run with low-privileged user accounts. Patches are available through vendor updates, including Red Hat Enterprise Linux errata.
Affected products
- F5 NGINX NGINX Open Source
- F5 NGINX NGINX Plus
- Red Hat Enterprise Linux AppStream 8, 9, 10
- Red Hat Update Infrastructure (RHUI) 5.1
Timeline
- 2026-03-24: disclosed
- 2026-03-24: advisory: Initial NVD publication
- 2026-05-05: patched: Red Hat released security updates for RHEL 10.0 EUS
References
- https://my.f5.com/manage/s/article/K000160382
- https://access.redhat.com/errata/RHSA-2026:10065
- https://access.redhat.com/errata/RHSA-2026:13634
- https://access.redhat.com/errata/RHSA-2026:13680
- https://access.redhat.com/errata/RHSA-2026:13839
- https://access.redhat.com/errata/RHSA-2026:14836
- https://access.redhat.com/errata/RHSA-2026:15942