CVE-2026-27651Patch(f5 / nginx_open_source)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 nginx_open_source systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_open_source
  • nginx_plus

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 6 mentions (2026-03-26); latest day: 1
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
nginx_open_sourcenginx_plus

3 versions affected across 2 products

Deep dive

Activity timeline11 mentions / 4d
02356Mentions · 2026-03-24: 3Mentions · 2026-03-26: 6Mentions · 2026-03-30: 1Mentions · 2026-05-20: 1Patch / Workaround · 2026-03-26: 6Technical Details · 2026-03-24: 3Technical Details · 2026-05-20: 103-2403-2603-3005-20
Signal classification3 categories
Patch
654.5%
Disclosure
436.4%
General
19.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure2General1
2026-03-266
Patch6
2026-03-301
Disclosure1
2026-05-201
Disclosure1
Full discourse11 posts
  • dbugs@ptdbugs
    Disclosure

    NGINX ngx_mail_auth_http_module vulnerability CVE: CVE-2026-27651 PT-Identifier: PT-2026-27429 Vendor: F5 Product: NGINX Open Source CVSS: 7.5 Credits: F5 acknowledges Arkadi Vainbrand for bringing this issue to our attention and following the highest standards of coordinated disclosure. Description: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27651 • https://my.f5.com/manage/s/article/K000160383 #dbugs_vuln

    Post summary

    The article announces the CVE‑2026‑27651 vulnerability in NGINX's ngx_mail_auth_http_module, detailing its impact, CVSS score of 7.5, and conditions under which worker process termination occurs, with references to vendor advisories.

    06025122.3K
    746 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23877/

    Post summary

    The Kusanagi‑nginx module has been updated to 1.28.3-1.el9, addressing multiple CVEs as part of a patch release.

    0202085
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23884/

    Post summary

    This post announces a module update that includes fixes for several CVEs, but it does not provide any PoC, exploit details, or evidence of active exploitation.

    0101091
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23870/

    Post summary

    An update for kusanagi-nginx129 includes patches for several CVE-2026 vulnerabilities, providing a fix for the affected modules.

    0101086
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23864/

    Post summary

    The kusanagi-nginx129 1.29.7‑1.el9 module update references several CVEs, indicating that the release includes fixes for those vulnerabilities.

    01010100
    200 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-27651 | F5 NGINX Open Source/NGINX Plus Response Header ngx_mail_auth_http_module null pointer dereference (K000160383 / Nessus ID 303484) https://ift.tt/kLIaipT A vulnerability categorized as problematic has been discovered in F5 NGINX Open Source and NGINX Plus. Aff…

    Post summary

    The post announces a new null pointer dereference vulnerability (CVE‑2026‑27651) affecting F5 NGINX Open Source and NGINX Plus, providing the technical nature of the flaw but no PoC, exploit, or mitigation details.

    0000053
    974 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos NGINX ❗ CVE-2026-32647 ❗ CVE-2026-27654 ❗ CVE-2026-27651 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-nginx/ https://t.co/o4ory9vuST

    Post summary

    The tweet announces three NGINX CVEs and provides links for further information, but it offers no technical details, PoC, exploits, or patch guidance.

    00000151
    6.6K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 Module Update 1.28.3-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx128 1.28.3-1 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651,... https://kusanagi.tokyo/en/releases/23885/

    Post summary

    KUSANAGI released a new nginx module version that patches multiple CVEs, providing a vendor patch update.

    0000054
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 Module Update 1.29.7-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nginx129 1.29.7-1 This update includes support for vulnerability(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651,... https://kusanagi.tokyo/en/releases/23871/

    Post summary

    The notification announces a Kusanagi module update that patches several CVEs, with no evidence of PoC, exploit, or active exploitation.

    0000054
    200 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27651 NGINX Mail Module Authentication Vulnerability Causing Worker Process Termination https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27651

    Post summary

    The notice announces a new NGINX Mail Module authentication flaw that triggers worker process termination, without any PoC, exploit, or patch information.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27651 When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may … https://www.cve.org/CVERecord?id=CVE-2026-27651

    Post summary

    A brief note that the ngx_mail_auth_http_module may cause worker process termination when enabled, but no PoC, exploitation, or patch details are provided.

    0000088
    56.8K followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_open_source---
Appf5nginx_plus---
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr35--
Appf5nginx_plusr35--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--

Explore more