PT-2026-27429 · Nginx+4 · Nginx Open Source+6
Published
2026-03-24
·
Updated
2026-05-20
·
CVE-2026-27651
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
NGINX Open Source (affected versions not specified)
NGINX Plus (affected versions not specified)
Description
When the
ngx mail auth http module module is enabled, certain undisclosed requests can lead to the termination of worker processes. This occurs when CRAM-MD5 or APOP authentication is enabled and the authentication server responds with the Auth-Wait header, allowing retries.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Rocky Linux
Ubuntu