CVE-2026-27651: NGINX ngx_mail_auth_http_module vulnerability
Last updated 6 June 2026
Other sources
NGINX ngxmailauthhttpmodule vulnerability
— Microsoft
When the ngxmailauthhttpmodule module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header.
— F5
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 36 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.29.71.28.3 - Upgrade
Upgrade
debian/nginxto a version that resolves this vulnerability.Fixed in 1.18.0-6.1+deb11u6Fixed in 1.22.1-9+deb12u6Fixed in 1.22.1-9+deb12u7Fixed in 1.26.3-3+deb13u4Fixed in 1.26.3-3+deb13u5Fixed in 1.30.1-3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27651?
CVE-2026-27651 is rated as a high severity vulnerability affecting NGINX Plus and NGINX Open Source.
How do I fix CVE-2026-27651?
To fix CVE-2026-27651, update to the latest stable version of NGINX Plus or NGINX Open Source as specified in the vendor's advisory.
Which versions of NGINX are affected by CVE-2026-27651?
CVE-2026-27651 affects NGINX Plus version 32 and NGINX Open Source versions up to 1.29.6 and from 0.5.15 to 0.9.7.
What types of authentication are involved in CVE-2026-27651?
This vulnerability involves CRAM-MD5 and APOP authentication methods when the ngx_mail_auth_http_module is enabled.
What are the potential consequences of CVE-2026-27651?
Exploitation of CVE-2026-27651 can lead to worker process termination, resulting in service interruptions.