CVE-2026-27651

moderate-risk
Published 2026-03-24

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Do I need to act?

-
0.04% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (12)

Nginx Open Source
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus
Nginx Plus

Affected Vendors

F5

References (1)

43
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 0/34 · Minimal
Exposure 17/34 · Moderate