Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-32647 Details

Description

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-125Out-of-bounds Readredhat-SADP
CWE-125Out-of-bounds Read[email protected]

Affected Products

ProductVersions
f5 nginx plus
r32 p1
r32 p2
r32 p3
r32 p4
r33

CPE

  • cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r35:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*
  • cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*

Remediation

  • No remediation found in references.
f5 nginx open source
>= 1.1.19, < 1.28.3
>= 1.29.0, < 1.29.7

CPE

  • cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-32647
NVD Published Date:
Mar 24, 2026
NVD Last Modified:
Jul 15, 2026
Source:
[email protected]
CVE-2026-32647 Details - Not Deferred