CVE-2026-27651
NGINX vulnerability analysis and mitigation

Overview

CVE-2026-27651 is a NULL Pointer Dereference vulnerability in the ngx_mail_auth_http_module of NGINX Plus and NGINX Open Source that allows unauthenticated remote attackers to crash worker processes, resulting in denial of service. The vulnerability was published on March 24, 2026, and affects NGINX Open Source versions 0.5.15 through 1.28.2 and 1.29.0 through 1.29.6, as well as NGINX Plus releases R32 through R36 (before specific patch levels). It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (F5 Advisory, Red Hat CVE).

Technical details

The root cause is a NULL Pointer Dereference (CWE-476) in the ngx_mail_auth_http_module. The flaw is triggered when two specific conditions are met simultaneously: (1) CRAM-MD5 or APOP authentication is enabled, and (2) the upstream authentication server returns an Auth-Wait response header permitting retry. Under these conditions, specially crafted undisclosed requests cause NGINX worker processes to dereference a null pointer and terminate. The attack requires no authentication, no user interaction, and no special privileges — only network access to the NGINX mail service (F5 Advisory, Red Hat CVE).

Impact

Successful exploitation causes NGINX worker processes to crash, resulting in denial of service for all services handled by those workers. An unauthenticated remote attacker can repeatedly trigger the crash to sustain service disruption, potentially completely disabling NGINX mail proxy functionality. There is no confidentiality or integrity impact — the vulnerability is limited to availability, affecting NGINX Open Source versions 0.5.15–1.28.2 and 1.29.0–1.29.6, and NGINX Plus R32 through R36 before their respective patch levels (F5 Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing NGINX instances with mail proxy functionality enabled (e.g., using Shodan or Censys with NGINX mail service banners), targeting versions in the affected range.
  2. Verify preconditions: Confirm that the target NGINX instance has ngx_mail_auth_http_module enabled with CRAM-MD5 or APOP authentication configured, and that the backend authentication server returns Auth-Wait headers on failed attempts.
  3. Craft malicious request: Send a specially crafted undisclosed mail authentication request to the NGINX mail proxy port (typically 25, 110, 143, or 993/995 for SMTP/POP3/IMAP) that triggers the null pointer dereference in the authentication HTTP module.
  4. Trigger worker crash: The malformed request causes the NGINX worker process handling the connection to dereference a null pointer and terminate, resulting in denial of service.
  5. Sustain DoS: Repeat the request to crash newly spawned worker processes, maintaining service disruption (F5 Advisory).

Indicators of compromise

  • Logs: Repeated NGINX worker process crash entries in system logs (e.g., nginx: worker process ... exited on signal 11 in /var/log/nginx/error.log or syslog); unexpected segfault entries in kernel logs associated with the nginx worker process.
  • Process: Frequent respawning of NGINX worker processes by the master process; abnormal termination of worker processes correlated with incoming mail authentication requests.
  • Network: Unusual or malformed SMTP/POP3/IMAP authentication requests to the NGINX mail proxy port from external sources, particularly those triggering Auth-Wait retry flows with CRAM-MD5 or APOP methods.

Mitigation and workarounds

F5 has released patches for all affected branches: NGINX Open Source should be upgraded to version 1.28.3 or 1.29.7 (or later); NGINX Plus should be upgraded to R32 P5, R35 P2, or R36 P3 (or later) (F5 Advisory). As an interim workaround, disable the ngx_mail_auth_http_module if mail proxy functionality is not required, or restrict network access to the mail authentication service. Red Hat has issued errata (RHSA-2026:6906, RHSA-2026:6907, RHSA-2026:6923, and others) for affected RHEL versions, and Ubuntu, SUSE, Debian, and Amazon Linux have also released updated packages (Red Hat Errata, NGINX Releases).

Community reactions

F5/NGINX published an official security advisory (K000160383) detailing the vulnerability and patch guidance. Red Hat tracked the issue and issued multiple errata across RHEL versions. The vulnerability received coverage from security news outlets including SecurityOnline and SecureReading, which noted it as part of a broader NGINX security update. Community discussion was observed on Mastodon and Bluesky, with general consensus that the patch should be applied promptly given NGINX's widespread deployment (F5 Advisory, NGINX Security Advisories).

Additional resources


SourceThis report was generated using AI

Related NGINX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42533CRITICAL9.2
  • NGINX logoNGINX
  • nginx-mod-http-geoip-debuginfo
NoYesJul 15, 2026
CVE-2026-42530CRITICAL9.2
  • NGINX logoNGINX
  • nginx-mod-stream-debuginfo
NoYesJun 17, 2026
CVE-2026-60005HIGH8.8
  • NGINX logoNGINX
  • nginx-mod-modsecurity-debugsource
NoYesJul 15, 2026
CVE-2026-56434HIGH8.3
  • NGINX logoNGINX
  • nginx-mod-brotli
NoYesJul 15, 2026
CVE-2026-48142MEDIUM6.3
  • NGINX logoNGINX
  • nginx-filesystem
NoYesJun 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management