logo

F5 NGINX Plus & Open‑Source Flaw Lets Attackers Execute Code via MP4 File

ID: c6dfca9e-87f5-5709-92b5-3d6af4980b21

STIX ID: report--c6dfca9e-87f5-5709-92b5-3d6af4980b21

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Divya

...
...

F5 disclosed CVE-2026-32647, a high-severity out-of-bounds read in the NGINX ngx_http_mp4_module (CVSS v4.0 8.5 / CVSS v3.1 7.8) that allows authenticated local attackers who can upload or trigger processing of crafted MP4 files to cause DoS and, in certain circumstances, achieve remote code execution. Affected versions include NGINX Plus R32–R36 (patches R36 P3, R35 P2, R32 P5) and NGINX Open Source 1.1.19–1.29.6 (fixed in 1.29.7 and 1.28.3); mitigations include disabling the mp4 pseudo-streaming directives or limiting uploads to trusted users until updates are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.