CVE-2026-27651
published 2026-03-24CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.92%
56.6th percentile
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.28.3-1 (forky) | nginx 1.28.3-1 (forky) |
| f5 | nginx | >= 0 < 1.28.3-1 | 1.28.3-1 |
| f5 | nginx_open_source | — | — |
| f5 | nginx_open_source | >= 0.5.15 < 1.28.3 | 1.28.3 |
| f5 | nginx_open_source | 0.5.15 – 0.9.7 | — |
| f5 | nginx_open_source | >= 1.0.0 < 1.28.3 | 1.28.3 |
| f5 | nginx_open_source | >= 1.29.0 < 1.29.7 | 1.29.7 |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R32 < R32 P5 | R32 P5 |
| f5 | nginx_plus | >= R33 < * | * |
| f5 | nginx_plus | >= R34 < * | * |
| f5 | nginx_plus | >= R35 < R35 P2 | R35 P2 |
| f5 | nginx_plus | >= R36 < R36 P3 | R36 P3 |
| f5 | nginx_plus | >= r33 < r35 | r35 |
| msrc | azl3_nginx_1.28.2-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
vendor_msrc7.5HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-03·CVSS 6.3
CVE-2026-1642 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that the nginx ngx_mail_smtp_module module incorrectly
handled certain memory operations when doing SMTP authentication. This
could possibly result in sensitive information being sent to the
authentication server. (CVE-2025-53859)
It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server. (CVE-2026-1642)
It was discovered that the nginx ngx_mail_auth_http_module module
incorrectly handled certain requests. An attacker could possibly use this
issue to cause nginx to crash, resulting in a denial of service.
(CVE-2026-27651)
It was discovered that
Red Hat
NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
vendor_redhat·2026-03-24·CVSS 8.7
CVE-2026-27651 [HIGH] CWE-476 NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A flaw was found in NGINX, specifically within the ngx_mail_auth_http_module. When this module is enabled, and CRAM-MD5 or APOP authentication is active with an authentication server that permits retries, undisclosed requests can cause NGINX worker processes to terminate. This can lead t
F5
CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cau...
vendor_f5·2026-03-24·CVSS 7.5
CVE-2026-27651 [HIGH] CWE-476 CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cau...
CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cau...
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: NGINX Plus, Nginx Open Source
Affected Versions: 0.5.15 - 0.9.7; 1.0.0 - 1.28.3; 1.29.0 - 1.29.7; r32; r33 - r35; r35; r36
F5 Advisory Articles: K000160383
F5 References: https://my.f5.com/manage/s/article/K000160383
Microsoft
NGINX ngx_mail_auth_http_module vulnerability
vendor_msrc·2026-03-10·CVSS 7.5
CVE-2026-27651 [HIGH] CWE-476 NGINX ngx_mail_auth_http_module vulnerability
NGINX ngx_mail_auth_http_module vulnerability
Mariner: Mariner
f5: f5
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-27651: nginx - When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open...
vendor_debian·2026·CVSS 8.7
CVE-2026-27651 [HIGH] CVE-2026-27651: nginx - When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open...
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.28.3-1)
sid: resolved (fixed in 1.28.3-1)
trixie: open
VulDB
F5 NGINX Open Source/NGINX Plus Response Header ngx_mail_auth_http_module null pointer dereference (K000160383 / Nessus ID 303484)
vuldb·2026-04-14·CVSS 8.7
CVE-2026-27651 [HIGH] F5 NGINX Open Source/NGINX Plus Response Header ngx_mail_auth_http_module null pointer dereference (K000160383 / Nessus ID 303484)
A vulnerability categorized as problematic has been discovered in F5 NGINX Open Source and NGINX Plus. Affected is the function ngx_mail_auth_http_module of the component Response Header Handler. Executing a manipulation can lead to null pointer dereference.
This vulnerability is registered as CVE-2026-27651. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-82w2-x7hf-5h8r: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate
ghsa_unreviewed·2026-03-24
CVE-2026-27651 [HIGH] CWE-476 GHSA-82w2-x7hf-5h8r: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
OSV
CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate
osv·2026-03-24·CVSS 8.7
CVE-2026-27651 [HIGH] CVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled [fedora-all]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-27651 [HIGH] CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled [fedora-all]
CVE-2026-27651 nginx: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-4de4d247a0 (nginx-1.28.3-1.fc44, nginx-mod-brotli-1.0.0~rc-7.fc44, and 5 more) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-4de4d247a0
---
FEDORA-2026-4de4d247a0 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-4d
Bugzilla
CVE-2026-27651 NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-27651 [HIGH] CVE-2026-27651 NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
CVE-2026-27651 NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:6906 https://access.redhat.com/errata/RHSA-2026:6906
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:
Wiz
CVE-2026-27651 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-27651 [HIGH] CVE-2026-27651 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27651 :
NGINX vulnerability analysis and mitigation
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source : NVD
## 8.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
NGINX
Nginx Plus
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.5
Exploitation Probability (EPSS) N/A
Affected
https://my.f5.com/manage/s/article/K000160383https://access.redhat.com/errata/RHSA-2026:10065https://access.redhat.com/errata/RHSA-2026:13634https://access.redhat.com/errata/RHSA-2026:13680https://access.redhat.com/errata/RHSA-2026:13839https://access.redhat.com/errata/RHSA-2026:14836https://access.redhat.com/errata/RHSA-2026:15942https://access.redhat.com/errata/RHSA-2026:15943https://access.redhat.com/errata/RHSA-2026:15945https://access.redhat.com/errata/RHSA-2026:15966https://access.redhat.com/errata/RHSA-2026:6906https://access.redhat.com/errata/RHSA-2026:6907https://access.redhat.com/errata/RHSA-2026:6923https://access.redhat.com/errata/RHSA-2026:7002https://access.redhat.com/errata/RHSA-2026:7343https://access.redhat.com/errata/RHSA-2026:8346https://access.redhat.com/security/cve/CVE-2026-27651https://bugzilla.redhat.com/show_bug.cgi?id=2450791https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27651.json
2026-03-24
Published