CVE-2026-27651 is a high-severity vulnerability (CVSS 7.5) affecting NGINX Plus and NGINX Open Source when the ngx_mail_auth_http_module is enabled. This flaw allows undisclosed network requests to cause worker processes to terminate, leading to a denial of service, particularly when CRAM-MD5 or APOP authentication is active and the authentication server permits retries. The attack complexity is low, requiring no privileges or user interaction to exploit. Currently, there is no evidence of active exploitation, nor are public exploit codes available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.5.15, <= 0.9.7CPE matchmatch criteria | cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.28.3CPE matchmatch criteria | cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* | ||
>= 1.29.0, < 1.29.7CPE matchmatch criteria | cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* | ||
>= r33, < r35CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* | ||
r32CPE matchmatch criteria | cpe:2.3:a:f5:nginx_plus:r32:-:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
NGINX ngx_mail_auth_http_module vulnerability
Mar 10, 2026NULL pointer dereference while using CRAM-MD5 or APOP
Jan 1, 2026NULL pointer dereference while using CRAM-MD5 or APOP
NULL pointer dereference while using CRAM-MD5 or APOP
NULL pointer dereference while using CRAM-MD5 or APOP