F5 NGINX Plus & Open‑Source Flaw Lets Attackers Execute Code via MP4 File
ID: c6dfca9e-87f5-5709-92b5-3d6af4980b21
STIX ID: report--c6dfca9e-87f5-5709-92b5-3d6af4980b21
Feed Name: GBHackers
F5 disclosed CVE-2026-32647, a high-severity out-of-bounds read in the NGINX ngx_http_mp4_module (CVSS v4.0 8.5 / CVSS v3.1 7.8) that allows authenticated local attackers who can upload or trigger processing of crafted MP4 files to cause DoS and, in certain circumstances, achieve remote code execution. Affected versions include NGINX Plus R32–R36 (patches R36 P3, R35 P2, R32 P5) and NGINX Open Source 1.1.19–1.29.6 (fixed in 1.29.7 and 1.28.3); mitigations include disabling the mp4 pseudo-streaming directives or limiting uploads to trusted users until updates are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
