nginxcritical
ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability
A critical vulnerability has been discovered in the NGINX HTTP WebDAV module that could allow remote attackers to execute arbitrary code. The flaw stems from improper validation of user-supplied data during WebDAV request parsing, leading to an integer underflow. This could enable an attacker to run code with the privileges of the service account on affected NGINX installations.