
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27651 is a NULL Pointer Dereference vulnerability in the ngx_mail_auth_http_module of NGINX Plus and NGINX Open Source that allows unauthenticated remote attackers to crash worker processes, resulting in denial of service. The vulnerability was published on March 24, 2026, and affects NGINX Open Source versions 0.5.15 through 1.28.2 and 1.29.0 through 1.29.6, as well as NGINX Plus releases R32 through R36 (before specific patch levels). It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (F5 Advisory, Red Hat CVE).
The root cause is a NULL Pointer Dereference (CWE-476) in the ngx_mail_auth_http_module. The flaw is triggered when two specific conditions are met simultaneously: (1) CRAM-MD5 or APOP authentication is enabled, and (2) the upstream authentication server returns an Auth-Wait response header permitting retry. Under these conditions, specially crafted undisclosed requests cause NGINX worker processes to dereference a null pointer and terminate. The attack requires no authentication, no user interaction, and no special privileges — only network access to the NGINX mail service (F5 Advisory, Red Hat CVE).
Successful exploitation causes NGINX worker processes to crash, resulting in denial of service for all services handled by those workers. An unauthenticated remote attacker can repeatedly trigger the crash to sustain service disruption, potentially completely disabling NGINX mail proxy functionality. There is no confidentiality or integrity impact — the vulnerability is limited to availability, affecting NGINX Open Source versions 0.5.15–1.28.2 and 1.29.0–1.29.6, and NGINX Plus R32 through R36 before their respective patch levels (F5 Advisory).
ngx_mail_auth_http_module enabled with CRAM-MD5 or APOP authentication configured, and that the backend authentication server returns Auth-Wait headers on failed attempts.nginx: worker process ... exited on signal 11 in /var/log/nginx/error.log or syslog); unexpected segfault entries in kernel logs associated with the nginx worker process.Auth-Wait retry flows with CRAM-MD5 or APOP methods.F5 has released patches for all affected branches: NGINX Open Source should be upgraded to version 1.28.3 or 1.29.7 (or later); NGINX Plus should be upgraded to R32 P5, R35 P2, or R36 P3 (or later) (F5 Advisory). As an interim workaround, disable the ngx_mail_auth_http_module if mail proxy functionality is not required, or restrict network access to the mail authentication service. Red Hat has issued errata (RHSA-2026:6906, RHSA-2026:6907, RHSA-2026:6923, and others) for affected RHEL versions, and Ubuntu, SUSE, Debian, and Amazon Linux have also released updated packages (Red Hat Errata, NGINX Releases).
F5/NGINX published an official security advisory (K000160383) detailing the vulnerability and patch guidance. Red Hat tracked the issue and issued multiple errata across RHEL versions. The vulnerability received coverage from security news outlets including SecurityOnline and SecureReading, which noted it as part of a broader NGINX security update. Community discussion was observed on Mastodon and Bluesky, with general consensus that the patch should be applied promptly given NGINX's widespread deployment (F5 Advisory, NGINX Security Advisories).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."