
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28753 is a CRLF injection vulnerability in the ngx_mail_smtp_module of NGINX Plus and NGINX Open Source, caused by improper handling of CRLF sequences in DNS responses. It allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, enabling request manipulation. The vulnerability was published on March 24, 2026, and affects NGINX Open Source versions 0.6.27 through 1.28.2 and 1.29.0 through 1.29.6, as well as NGINX Plus R32 through R36 (various patch levels). It carries a CVSS v3.1 base score of 3.7 (Low) and a CVSS v4.0 base score of 6.3 (Medium) (F5 Advisory, Red Hat).
The root cause is classified as CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection). When NGINX's mail SMTP module processes DNS responses to resolve upstream SMTP server hostnames, it fails to sanitize CRLF (\r\n) sequences embedded in those responses. An attacker who controls a DNS server can craft malicious DNS responses containing CRLF sequences, which NGINX then incorporates into SMTP protocol headers without proper escaping, effectively injecting arbitrary SMTP headers into upstream requests. Exploitation requires the attacker to have control over a DNS server that the NGINX instance queries (high attack complexity), and the ngx_mail_smtp_module must be actively configured and in use (F5 Advisory, Red Hat).
Successful exploitation allows an attacker to manipulate SMTP upstream requests by injecting arbitrary headers, potentially altering email routing, modifying SMTP protocol commands, or tampering with message metadata. The integrity of SMTP communications handled by the affected NGINX instance is at risk; confidentiality and availability are not directly impacted. The attack scope is limited to the SMTP mail proxy functionality and does not provide code execution or direct access to system resources (F5 Advisory).
ngx_mail_smtp_module as an SMTP proxy, and determine the DNS resolver(s) they use for upstream hostname resolution.\r\n) followed by arbitrary SMTP header content within the resolved hostname or associated record data.ngx_mail_smtp_module incorporates the unsanitized CRLF-containing data into the SMTP upstream request, injecting attacker-controlled headers or commands into the SMTP session, potentially manipulating email routing or protocol behavior (F5 Advisory, Red Hat).F5 has released patched versions addressing this vulnerability. For NGINX Open Source, update to version 1.28.3 (stable branch) or 1.29.7 (mainline branch). For NGINX Plus, update to R32 P5, R35 P2, or R36 P3 or later; versions R33 and R34 have reached End of Technical Support and will not receive patches, requiring immediate upgrade to a supported release. As a workaround, if the SMTP mail proxy module is not actively used, disabling it reduces exposure. Additionally, restricting DNS resolution to trusted, internal resolvers and implementing network segmentation can limit the attack surface (F5 Advisory).
The vulnerability received routine coverage from Linux distribution security teams, with advisories issued by Red Hat, SUSE, openSUSE, Debian, Ubuntu, and Amazon Linux shortly after disclosure (Red Hat, SUSE Advisory, Ubuntu Advisory). The oss-security mailing list carried a disclosure post, and the vulnerability was tracked by multiple scanner vendors including Tenable (Nessus) and Qualys. Community reaction was measured given the low CVSS v3.1 score and the high exploitation complexity requiring DNS server control.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."