---
schema_version: '1.0'
id: security-20260705-7c3ab1
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-27654
url_hash: 7c3ab19cbe791fac2a473a0ba52d40473f8370628c4c0f0dbb5030ab9186be3b
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-27654
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-27654
- severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- nginx
- Debian
lang: en
published_at: '2026-03-24T15:16:33Z'
fetched_at: '2026-07-05T15:34:33Z'
updated_at: '2026-07-05T15:34:52Z'
status: published
content_hash: f94e7b1fde54e17e00e5a749bde50127106603508fef246b27f0e9d6c3cb5dcf
license_note: full
summary: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module
  module that might allow an attacker to trigger a buffer overflow to the NGINX worker
  process; this vulnerability may result in termination of the NGINX worker process
  or modification of source or des
summary_source: rss
summary_en: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module
  module that might allow an attacker to trigger a buffer overflow to the NGINX worker
  process; this vulnerability may result in termination of the NGINX worker process
  or modification of source or des
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-27654 — nginx
---

# DEBIAN-CVE-2026-27654 — nginx

## TL;DR
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or des

## Key Points
- cve / DEBIAN-CVE-2026-27654 / severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X / nginx / Debian

## Details
**Severity:** CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
**Advisory:** DEBIAN-CVE-2026-27654

**Affected (your watchlist):**
- `Debian:nginx` 1.22.1-9+deb12u1 → no fixed version listed [proxmox]

**Details:**
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-27654

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-27654_

## Source
元記事: [DEBIAN-CVE-2026-27654 — nginx](https://osv.dev/vulnerability/DEBIAN-CVE-2026-27654) — published 2026-03-24T15:16:33Z
