PT-2026-27429 · Nginx+4 · Nginx Open Source+6

Published

2026-03-24

·

Updated

2026-05-20

·

CVE-2026-27651

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NGINX Open Source (affected versions not specified) NGINX Plus (affected versions not specified)
Description When the ngx mail auth http module module is enabled, certain undisclosed requests can lead to the termination of worker processes. This occurs when CRAM-MD5 or APOP authentication is enabled and the authentication server responds with the Auth-Wait header, allowing retries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2026:6906
ALSA-2026:6907
ALSA-2026:6923
ALSA-2026:7002
ALSA-2026:7343
BDU:2026-04820
BIT-NGINX-2026-27651
BIT-NGINX-GATEWAY-2026-27651
CVE-2026-27651
OPENSUSE-SU-2026:10423-1
RHSA-2026:13634
RHSA-2026:13680
RHSA-2026:13839
RHSA-2026:14836
RHSA-2026:15942
RHSA-2026:15943
RHSA-2026:15945
RHSA-2026:15966
RHSA-2026:6906
RHSA-2026:6907
RHSA-2026:6923
RHSA-2026:7002
RHSA-2026:7343
RHSA-2026:8346
USN-8210-1

Affected Products

Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu