CVE-2026-27654
HighAdvisory
Published 24 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.8
- base score, highest
- EPSS
- 0.251
- 98th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 29
- of 17,781 indexed, latest versions
- Container images
- 30
- deployed by those charts
- Fix available
- 5 of 5
- affected packages
NGINX ngx_http_dav_module vulnerability
Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 30 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nginxdeb | 1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+10 more | 1.4.6-1ubuntu3.9+esm6, 1.18.0-0ubuntu1.7+esm1, 1.18.0-6ubuntu14.10, 1.22.1-9+deb12u5+2 more | 18 |
| nginxapk | 1.28.0-r3, 1.28.1-r1, 1.28.2-r1 | 1.28.3-r0 | 7 |
| nginxbitnami | 1.25.5-0, 1.27.1-2, 1.28.0-0 | 1.28.3 | 3 |
| nginx-mainlineapk | 1.27.4-r0, 1.27.4-r2 | 1.29.7-r0 | 2 |
| NGINX Open Sourcebitnami | 1.25.5-0 | 1.28.3 | 1 |
- OSV records
- ALPINE-CVE-2026-27654BIT-nginx-2026-27654CGA-272c-r2vx-c7h2DEBIAN-CVE-2026-27654UBUNTU-CVE-2026-27654
- Also known as
- BIT-nginx-gateway-2026-27654, CGA-m338-cq23-g3qv, USN-8210-1, USN-8375-1
Charts affected
29 by stars
Container images carrying it
30 by charts deploying them
A fixed version is listed for 5 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| allegroai/ | 713ae38f7daf | nginx | 1.22.1-9+deb12u5 | 1 |
| awesometechnologies/ | a1c1f4662875 | nginx | 1.28.3-r0 | 1 |
| bitnamilegacy/ | 934d1acd5ca8 | nginx | 1.28.3 | 1 |
| bitnamilegacy/ | eaf9066e86f6 | nginx | 1.28.3 | 1 |
| fnzv/ | b3079b95c336 | nginx | 1.18.0-6ubuntu14.10 | 1 |
| galaxy/ | 8e577a626dfd | nginx | 1.4.6-1ubuntu3.9+esm6 | 1 |
| heartexlabs/ | aa461572e8f9 | nginx | 1.28.3-r0 | 1 |
| intel/ | 1a89327e499b | nginx | 1.18.0-0ubuntu1.7+esm1 | 1 |
| jeboehm/ | 9da13edf5aa8 | nginx | 1.28.3-r0 | 1 |
| mrasif/ | 375a1ed8fdc0 | nginx | 1.28.3-r0 | 1 |
| rocketadmin/ | 10955ef540b9 | nginx | 1.22.1-9+deb12u5 | 1 |
| seafileltd/ | 6693911bcc40 | nginx | 1.18.0-0ubuntu1.7+esm1 | 1 |
| seafileltd/ | 7ac833196f60 | nginx | 1.18.0-0ubuntu1.7+esm1 | 1 |
| seafileltd/ | ed0fcda5e6a9 | nginx | 1.18.0-0ubuntu1.7+esm1 | 1 |
| sigp/ | 2c219b04758e | nginx | 1.22.1-9+deb12u5 | 1 |
| tinymediamanager/ | 2b34dc85099e | nginx | 1.26.3-3+deb13u3 | 1 |
| vabene1111/ | 0f8d061895e9 | nginx | 1.28.3-r0 | 1 |
| xeladock/ | 4baf531453f1 | nginx | 1.18.0-6ubuntu14.10 | 1 |
| xeladock/ | c259a67b1dff | nginx | 1.18.0-6ubuntu14.10 | 1 |
| zabbix/ | 0e5f69c4c54e | nginx | 1.24.0-2ubuntu7.7 | 1 |
| zabbix/ | 7d4d58086515 | nginx | 1.24.0-2ubuntu7.7 | 1 |
| gcr.io/ | 991c1465c658 | nginx-mainline | 1.29.7-r0 | 1 |
| gcr.io/ | a535f7de024b | nginx-mainline | 1.29.7-r0 | 1 |
| ghcr.io/ | 72f35584026d | nginx | 1.22.1-9+deb12u5 | 1 |
| ghcr.io/ | 24efef013a53 | nginx | 1.18.0-0ubuntu1.7+esm1 | 1 |
| ghcr.io/ | afb3e9282952 | nginx | 1.18.0-6ubuntu14.10 | 1 |
| ghcr.io/ | a6e3e996a4ae | nginx | 1.28.3-r0 | 1 |
| ghcr.io/ | 9665c3e71889 | nginx | 1.28.3-r0 | 1 |
| ghcr.io/ | d19d886d5090 | nginx | 1.22.1-9+deb12u5 | 1 |
| ghcr.io/ | 344f53763b25 | nginx NGINX Open Source | 1.28.3 1.28.3 | 1 |