Executive brief
NGINX, a widely used web and proxy server, contains a vulnerability in its MP4 video processing module. An attacker who can provide a malicious video file to the server could cause the software to crash or potentially execute unauthorized code. This could lead to a disruption of web services or unauthorized access to the server's memory and data.
Technical details
A vulnerability exists in the ngx_http_mp4_module of NGINX Open Source and NGINX Plus. The flaw is triggered when the module processes a specially crafted MP4 file, leading to a buffer over-read or over-write in the NGINX worker memory. This issue requires the NGINX instance to be built with the ngx_http_mp4_module and have the 'mp4' directive active in the configuration. An attacker with the ability to trigger the processing of such a file (typically requiring local or low-privileged access to upload or point the server to the file) can cause a denial of service via process crash or potentially achieve arbitrary code execution. Red Hat has released security advisories (e.g., RHSA-2026:13634) providing patches for affected Enterprise Linux versions.
Affected products
- NGINX NGINX Open Source All versions built with ngx_http_mp4_module and mp4 directive enabled
- NGINX NGINX Plus All versions built with ngx_http_mp4_module and mp4 directive enabled
- Red Hat Red Hat Enterprise Linux 8, 9, 10.0, 10.1
Timeline
- 2026-03-24: disclosed: Initial publication date
- 2026-04-23: patched: Red Hat released initial security updates (RHSA-2026:10065)
References
- https://my.f5.com/manage/s/article/K000160366
- https://access.redhat.com/errata/RHSA-2026:10065
- https://access.redhat.com/errata/RHSA-2026:13634
- https://access.redhat.com/errata/RHSA-2026:13680
- https://access.redhat.com/errata/RHSA-2026:13839
- https://access.redhat.com/errata/RHSA-2026:14836
- https://access.redhat.com/errata/RHSA-2026:15942