CVE-2026-32647 Details
Description
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in the ngx_http_mp4_module of NGINX Open Source and NGINX Plus, which could allow an attacker to manipulate an MP4 file in a way that causes a buffer over-read or over-write in the NGINX worker memory. This could lead to the termination of the worker process or potentially allow for code execution. The vulnerability is present only if the MP4 module is enabled and the mp4 directive is used in the NGINX configuration. Exploitation requires the ability to process a specially crafted MP4 file with the ngx_http_mp4_module.
To address this vulnerability, users can update to NGINX Open Source version 1.29.7 or 1.28.3, or NGINX Plus versions R36 P3, R35 P2, or R32 P5. If an immediate update is not possible, the MP4 module can be disabled in the NGINX configuration by commenting out the mp4 directives. After making this change, NGINX should be reloaded to apply the new configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | redhat-SADP |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx plus | r32 p1 r32 p2 r32 p3 r32 p4 r33 r33 p1 r33 p2 r33 p3 r34 r34 p1 r34 p2 r35 r35 p1 r36 r36 p1 r36 p2 |
CPE
Remediation
| |
| f5 nginx open source | >= 1.1.19, < 1.28.3 >= 1.29.0, < 1.29.7 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |