Severity
6.3MEDIUM
EPSS
0.0%
top 93.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateAug 25

Description

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built wit

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages6 packages

CVEListV5f5/nginx_open_source0.71.29.1
NVDf5/nginx_open_source0.7.221.29.1
CVEListV5f5/nginx_plusR34R34 P2+4
NVDf5/nginx_plus5 versions+4
Alpinenginx< 1.28.2-r0+1

🔴Vulnerability Details

4
CVEList
NGINX ngx_mail_smtp_module vulnerability2025-08-13
OSV
CVE-2025-53859: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP2025-08-13
GHSA
GHSA-2qmj-q2xc-85v8: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP2025-08-13
OSV
CVE-2025-53859: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP2025-08-13

📋Vendor Advisories

6
Ubuntu
nginx vulnerability2025-08-25
Red Hat
nginx: NGINX ngx_mail_smtp_module vulnerability2025-08-13
F5
CVE-2025-53859: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated...2025-08-13
Microsoft
NGINX ngx_mail_smtp_module vulnerability2025-08-12
Debian
CVE-2025-53859: nginx - NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_modul...2025