CVE detail
CVE-2026-27654
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 5.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
19 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27654.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 24, 2026, 3:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2450776bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/security/cve/CVE-2026-27654access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:8346access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:7343access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:7002access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:6923access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:6907access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:6906access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:15966access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:15945access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:15943access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:15942access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:14836access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:13839access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:13680access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:13634access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:10065access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 24, 2026, 3:16 PM No excerpt available.
Vendor Advisorymy.f5.comMar 24, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.99 · max 1 stars
- Debajyoti0-0/CVE-2026-27654-PoCHigh confidencegithubRepository topic discovery1 starsDiscovered Jul 21, 2026, 12:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42055CVSS 9.2 · Critical
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2…
- CVE-2026-9256CVSS 9.2 · Critical
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct,…
- CVE-2026-42945CVSS 9.2 · Critical
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or…
- CVE-2026-42536CVSS 7.5 · High
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2…
- CVE-2026-34355CVSS 7.5 · High
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fi…
- CVE-2026-32741CVSS 7.1 · High
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF f…