Junglewise Threat Intelligence

CVE-2026-32647: NGINX Open Source and Plus buffer overflow in ngx_http_mp4_module

CVE-2026-32647 · Severity: high · CVSS 7.8 · Published 2026-03-24

Technologies: Red Hat Enterprise Linux, NGINX Open Source. Vendors: Red Hat, NGINX.

Executive brief

NGINX, a widely used web and proxy server, contains a vulnerability in its MP4 video processing module. An attacker who can provide a malicious video file to the server could cause the software to crash or potentially execute unauthorized code. This could lead to a disruption of web services or unauthorized access to the server's memory and data.

Technical details

A vulnerability exists in the ngx_http_mp4_module of NGINX Open Source and NGINX Plus. The flaw is triggered when the module processes a specially crafted MP4 file, leading to a buffer over-read or over-write in the NGINX worker memory. This issue requires the NGINX instance to be built with the ngx_http_mp4_module and have the 'mp4' directive active in the configuration. An attacker with the ability to trigger the processing of such a file (typically requiring local or low-privileged access to upload or point the server to the file) can cause a denial of service via process crash or potentially achieve arbitrary code execution. Red Hat has released security advisories (e.g., RHSA-2026:13634) providing patches for affected Enterprise Linux versions.

Affected products

  • NGINX NGINX Open Source All versions built with ngx_http_mp4_module and mp4 directive enabled
  • NGINX NGINX Plus All versions built with ngx_http_mp4_module and mp4 directive enabled
  • Red Hat Red Hat Enterprise Linux 8, 9, 10.0, 10.1

Timeline

  • 2026-03-24: disclosed: Initial publication date
  • 2026-04-23: patched: Red Hat released initial security updates (RHSA-2026:10065)

References

Related threats