CVE-2022-41742

NGINX ngx_http_mp4_module vulnerability CVE-2022-41742

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.


We have discovered 1,824,159 live websites that are affected by CVE-2022-41742.

Run a Free Instant Scan




Affected Software

Product  Nginx
Category Web Servers
Vulnerable Domains1,824,159 live websites (56% of Nginx install base)
Vulnerable Versions
  • from * through 1.23.2
Vulnerable Versions Count196 versions ( 87% of all versions)


Common Weakness Enumeration

CWE-787 Out-of-bounds Write



Details

  • Published - Oct 19, 2022
  • Updated - May 8, 2025

Website Distribution by Country

Number of websites using CVE-2022-41742
United States469,925 websites



Russia414,733 websites
China116,917 websites
Germany107,663 websites
France68,932 websites
British Virgin Islands54,217 websites
Brazil52,022 websites
Singapore40,489 websites
Hong Kong39,698 websites
Italy38,895 websites

Website Distribution by TLD

Number of websites using CVE-2022-41742
.com591,738 websites
.ru401,632 websites
.cn62,893 websites
.org53,218 websites
.net51,998 websites
.com.br46,047 websites
.de43,896 websites
.it30,925 websites
.cz25,931 websites
.nl21,121 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-41742

Top websites that are affected by CVE-2022-41742. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
*.me British Virgin Islands***
******.de Germany***
****.******.org United States***
***.**.**.com China***
********.me British Virgin Islands***
**********.com United States***
*******.com United States***
*******.******.com United States***
************.ru Russia***
See full domain list

FAQ

CVE-2022-41742 is Out-of-bounds Write in Nginx
A total of 1,824,159 websites have been identified as vulnerable to CVE-2022-41742, based on global website indexing conducted by WebTechSurvey.
The Nginx is affected by the CVE-2022-41742 vulnerability.
Nginx versions up to 1.23.2 are vulnerable to CVE-2022-41742.
CVE-2022-41742 is resolved in version 1.23.2 of Nginx.