
NGINX ngx_mail_auth_http_module vulnerability CVE: CVE-2026-27651 PT-Identifier: PT-2026-27429 Vendor: F5 Product: NGINX Open Source CVSS: 7.5 Credits: F5 acknowledges Arkadi Vainbrand for bringing this issue to our attention and following the highest standards of coordinated disclosure. Description: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-27651 • https://my.f5.com/manage/s/article/K000160383 #dbugs_vuln
Post summary
The article announces the CVE‑2026‑27651 vulnerability in NGINX's ngx_mail_auth_http_module, detailing its impact, CVSS score of 7.5, and conditions under which worker process termination occurs, with references to vendor advisories.





