← Back to CVE List
CVE-2026-27651NVD
Vulnerability Summary
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS v4.0 Base Metrics — Score 8.7 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- F5 NGINX Open Source >= 1.29.0 and < 1.29.7
- F5 NGINX Open Source >= 0.5.15 and < 1.28.3
- F5 NGINX Plus >= R36 and < R36 P3
- F5 NGINX Plus >= R35 and < R35 P2
- F5 NGINX Plus >= R34 and < *
- F5 NGINX Plus >= R33 and < *
- F5 NGINX Plus >= R32 and < R32 P5
- F5 NGINX Open Source 1.29.7
- F5 NGINX Open Source 1.28.3
- F5 NGINX Plus R36 P3
- F5 NGINX Plus R35 P2
- F5 NGINX Plus *
- F5 NGINX Plus R32 P5