ANT-2026-VS18SA90 · nginx
arbitrary-file-write
MERGED
This finding was consolidated into ANT-2026-HY56VRSB after publication. Both entries described the same underlying vulnerability; the surviving finding carries the full report and the disclosure record. The original commitment below remains in the ledger.
UPSTREAM FIX
Advisories assigned to this finding before it was consolidated. The fix record is carried on the surviving finding.
https://nvd.nist.gov/vuln/detail/CVE-2026-27654
PROVENANCE
SHA-3-512 hash:
70c7065a7506628831667e565053165f8142abd80e67756200c4b6cb0d6c34fe0590d7f2fa655fbfd2cc36da73eeb98d23667209d18f2ca4ba3f2554e8194d1c
Committed 2026-04-05 16:37 PT
Revealed 2026-05-20 00:40 PT
Verify (download preimage.json)
Show preimage JSON
{
"ant_id": "ANT-2026-VS18SA90",
"bug_class": "Arbitrary File Write",
"claude_severity": "critical",
"commit_sha": null,
"created_at": "2026-03-29T20:40:17+00:00",
"description": "The nginx WebDAV module allows unauthenticated remote clients to write files to the server.",
"discovered_at": null,
"location": null,
"poc_sha256": null,
"preimage_version": 1,
"project": "nginx",
"reproduction": null,
"technical_details": null,
"title": "unauthenticated remote file write in nginx WebDAV module",
"vendor_severity": "critical"
}