#VU124480 Integer overflow in NGINX Open Source - CVE-2026-27784
Published: March 25, 2026
NGINX Open Source
F5 Networks
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the ngx_http_mp4_module module. A remote attacker can supply specially crafted MP4 data to the server, trigger an integer overflow and execute arbitrary code on the target system.
Note, the vulnerability affects only 32-bit NGINX Open Source deployments.