Home

Description

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED Reserved 2026-03-18 | Published 2026-03-24 | Updated 2026-03-24 | Assigner f5




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-476 NULL Pointer Dereference

Product status

Default status
unknown

1.29.0 (semver) before 1.29.7
affected

0.5.15 (semver) before 1.28.3
affected

Default status
unaffected

R36 (custom) before R36 P3
affected

R35 (custom) before R35 P2
affected

R34 (custom) before *
affected

R33 (custom) before *
affected

R32 (custom) before R32 P5
affected

Credits

F5 acknowledges Arkadi Vainbrand for bringing this issue to our attention and following the highest standards of coordinated disclosure. reporter

References

my.f5.com/manage/s/article/K000160383 vendor-advisory

cve.org (CVE-2026-27651)

nvd.nist.gov (CVE-2026-27651)

Download JSON