CVE-2026-28753
NGINX vulnerability analysis and mitigation

Overview

CVE-2026-28753 is a CRLF injection vulnerability in the ngx_mail_smtp_module of NGINX Plus and NGINX Open Source, caused by improper handling of CRLF sequences in DNS responses. It allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, enabling request manipulation. The vulnerability was published on March 24, 2026, and affects NGINX Open Source versions 0.6.27 through 1.28.2 and 1.29.0 through 1.29.6, as well as NGINX Plus R32 through R36 (various patch levels). It carries a CVSS v3.1 base score of 3.7 (Low) and a CVSS v4.0 base score of 6.3 (Medium) (F5 Advisory, Red Hat).

Technical details

The root cause is classified as CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection). When NGINX's mail SMTP module processes DNS responses to resolve upstream SMTP server hostnames, it fails to sanitize CRLF (\r\n) sequences embedded in those responses. An attacker who controls a DNS server can craft malicious DNS responses containing CRLF sequences, which NGINX then incorporates into SMTP protocol headers without proper escaping, effectively injecting arbitrary SMTP headers into upstream requests. Exploitation requires the attacker to have control over a DNS server that the NGINX instance queries (high attack complexity), and the ngx_mail_smtp_module must be actively configured and in use (F5 Advisory, Red Hat).

Impact

Successful exploitation allows an attacker to manipulate SMTP upstream requests by injecting arbitrary headers, potentially altering email routing, modifying SMTP protocol commands, or tampering with message metadata. The integrity of SMTP communications handled by the affected NGINX instance is at risk; confidentiality and availability are not directly impacted. The attack scope is limited to the SMTP mail proxy functionality and does not provide code execution or direct access to system resources (F5 Advisory).

Exploitation steps

  1. Reconnaissance: Identify NGINX instances configured to use the ngx_mail_smtp_module as an SMTP proxy, and determine the DNS resolver(s) they use for upstream hostname resolution.
  2. DNS Server Compromise or Positioning: Gain control of a DNS server that the target NGINX instance queries — either by compromising an upstream resolver, performing DNS cache poisoning, or operating a rogue authoritative DNS server for a domain used as an SMTP upstream.
  3. Craft Malicious DNS Response: Prepare a DNS response for the SMTP upstream hostname that embeds CRLF sequences (e.g., \r\n) followed by arbitrary SMTP header content within the resolved hostname or associated record data.
  4. Trigger DNS Resolution: Cause the NGINX mail proxy to resolve the upstream SMTP hostname (e.g., by initiating an SMTP proxying session), so it receives the crafted DNS response.
  5. Header Injection: NGINX's ngx_mail_smtp_module incorporates the unsanitized CRLF-containing data into the SMTP upstream request, injecting attacker-controlled headers or commands into the SMTP session, potentially manipulating email routing or protocol behavior (F5 Advisory, Red Hat).

Indicators of compromise

  • Network: Unexpected or anomalous DNS responses for SMTP upstream hostnames containing unusual characters or extended data; DNS queries to untrusted or unexpected resolvers from the NGINX host.
  • Logs: NGINX mail proxy logs showing unexpected SMTP headers or commands in upstream sessions; SMTP server logs reflecting unusual or malformed headers originating from the NGINX proxy.
  • Network: Outbound SMTP connections to unexpected upstream servers or IP addresses not matching configured upstreams, potentially indicating redirected mail flow.

Mitigation and workarounds

F5 has released patched versions addressing this vulnerability. For NGINX Open Source, update to version 1.28.3 (stable branch) or 1.29.7 (mainline branch). For NGINX Plus, update to R32 P5, R35 P2, or R36 P3 or later; versions R33 and R34 have reached End of Technical Support and will not receive patches, requiring immediate upgrade to a supported release. As a workaround, if the SMTP mail proxy module is not actively used, disabling it reduces exposure. Additionally, restricting DNS resolution to trusted, internal resolvers and implementing network segmentation can limit the attack surface (F5 Advisory).

Community reactions

The vulnerability received routine coverage from Linux distribution security teams, with advisories issued by Red Hat, SUSE, openSUSE, Debian, Ubuntu, and Amazon Linux shortly after disclosure (Red Hat, SUSE Advisory, Ubuntu Advisory). The oss-security mailing list carried a disclosure post, and the vulnerability was tracked by multiple scanner vendors including Tenable (Nessus) and Qualys. Community reaction was measured given the low CVSS v3.1 score and the high exploitation complexity requiring DNS server control.

Additional resources


SourceThis report was generated using AI

Related NGINX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42533CRITICAL9.2
  • NGINX logoNGINX
  • nginx-mod-http-geoip-debuginfo
NoYesJul 15, 2026
CVE-2026-42530CRITICAL9.2
  • NGINX logoNGINX
  • nginx-mod-stream-debuginfo
NoYesJun 17, 2026
CVE-2026-60005HIGH8.8
  • NGINX logoNGINX
  • nginx-mod-modsecurity-debugsource
NoYesJul 15, 2026
CVE-2026-56434HIGH8.3
  • NGINX logoNGINX
  • nginx-mod-brotli
NoYesJul 15, 2026
CVE-2026-48142MEDIUM6.3
  • NGINX logoNGINX
  • nginx-filesystem
NoYesJun 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management