ANT-2026-VS18SA90 · nginx

arbitrary-file-write

CVE-2026-27654

MERGED

This finding was consolidated into ANT-2026-HY56VRSB after publication. Both entries described the same underlying vulnerability; the surviving finding carries the full report and the disclosure record. The original commitment below remains in the ledger.

UPSTREAM FIX

Advisories assigned to this finding before it was consolidated. The fix record is carried on the surviving finding.

https://nvd.nist.gov/vuln/detail/CVE-2026-27654

PROVENANCE

SHA-3-512 hash:

70c7065a7506628831667e565053165f8142abd80e67756200c4b6cb0d6c34fe0590d7f2fa655fbfd2cc36da73eeb98d23667209d18f2ca4ba3f2554e8194d1c

Committed 2026-04-05 16:37 PT

Revealed 2026-05-20 00:40 PT

Verify (download preimage.json)

Show preimage JSON
{
  "ant_id": "ANT-2026-VS18SA90",
  "bug_class": "Arbitrary File Write",
  "claude_severity": "critical",
  "commit_sha": null,
  "created_at": "2026-03-29T20:40:17+00:00",
  "description": "The nginx WebDAV module allows unauthenticated remote clients to write files to the server.",
  "discovered_at": null,
  "location": null,
  "poc_sha256": null,
  "preimage_version": 1,
  "project": "nginx",
  "reproduction": null,
  "technical_details": null,
  "title": "unauthenticated remote file write in nginx WebDAV module",
  "vendor_severity": "critical"
}