CVE-2026-28753Patch(f5 / nginx_open_source)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 nginx_open_source systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_open_source
  • nginx_plus

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-26); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
nginx_open_sourcenginx_plus

5 versions affected across 2 products

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-24: 2Mentions · 2026-03-26: 4Mentions · 2026-05-20: 1Patch / Workaround · 2026-03-26: 4Technical Details · 2026-03-24: 2Technical Details · 2026-05-20: 103-2403-2605-20
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-242
Disclosure2
2026-03-264
Patch4
2026-05-201
Disclosure1
Full discourse7 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23877/

    Post summary

    The release updates the nginx128 module to address six CVEs, providing a patch for these vulnerabilities.

    0202085
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx128 モジュール更新情報 1.28.3-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx128 1.28.3-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23884/

    Post summary

    This note announces a module update that includes patches for several CVE‑identified vulnerabilities, but offers no PoC, exploit code, or indication of active exploitation.

    0101091
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)への対応が含まれ... https://kusanagi.tokyo/releases/23870/

    Post summary

    The bulletin announces a module update that incorporates fixes for six CVEs, presenting a patch rather than providing exploit details or active exploitation claims.

    0101086
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nginx129 モジュール更新情報 1.29.7-1.el9 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nginx129 1.29.7-1.el9 この更新には脆弱性(CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755)... https://kusanagi.tokyo/releases/23864/

    Post summary

    Kusanagi-nginx129 has been updated to version 1.29.7-1.el9, providing patches for six CVEs.

    01010100
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28753 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows … https://www.cve.org/CVERecord?id=CVE-2026-28753

    Post summary

    The text announces CVE‑2026‑28753, detailing a CRLF handling flaw in NGINX’s mail SMTP module, but does not provide proof‑of‑concepts, exploits, or evidence of active attacks.

    01010103
    56.8K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-28753 | F5 NGINX Open Source/NGINX Plus ngx_mail_smtp_module crlf injection (K000160367 / Nessus ID 306671) https://ift.tt/gkVlAW7 A vulnerability described as problematic has been identified in F5 NGINX Open Source and NGINX Plus. This vulnerability affects the funct…

    Post summary

    A brief disclosure of CVE‑2026‑28753, highlighting a CRLF injection flaw in F5 NGINX Open Source/NGINX Plus, with no PoC, exploit code, active attack report, or patch information provided.

    0000050
    974 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28753 NGINX SMTP Module Vulnerability Enables Arbitrary Header Injection via DNS Response https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28753

    Post summary

    The text announces CVE‑2026‑28753, an NGINX SMTP module flaw that allows arbitrary header injection through DNS responses, but provides no PoC, exploit code, or active exploitation evidence.

    0000045
    4.0K followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appf5nginx_open_source---
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr33--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr34--
Appf5nginx_plusr35--
Appf5nginx_plusr35--
Appf5nginx_plusr36--
Appf5nginx_plusr36--
Appf5nginx_plusr36--

Explore more