Description
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
13.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (12)
F5/NGINX Open Source
0.5.15 - 1.28.3
F5/NGINX Open Source
1.29.0 - 1.29.7
F5/NGINX Plus
R32 - R32 P5
F5/NGINX Plus
R33
F5/NGINX Plus
R34
F5/NGINX Plus
R35 - R35 P2
F5/NGINX Plus
R36 - R36 P3
f5/nginx_open_source
0.5.15 - 0.9.7
f5/nginx_plus
r32 (5 CPE variants)
f5/nginx_plus
r35 (2 CPE variants)
... and 2 more
Published
Mar 24, 2026
Tracked Since
Mar 24, 2026