NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Mar 27, 2026 | Mar 24, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-mailUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-http-perlUpgrade nginx-coreUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-geoipUpgrade nginxUpgrade nginx-mod-develUpgrade nginx-filesystemUpgrade nginx-mod-stream | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-mod-mail-debuginfoUpgrade nginx-debuginfoUpgrade nginx-filesystemUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-core-debuginfoUpgrade nginx-mod-develUpgrade nginx-coreUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-debugsource | Apr 14, 2026 | Mar 24, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.28.3Upgrade to nginx version 1.29.7 | Mar 27, 2026 | Mar 24, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 24, 2026 |
| Ubuntu | — | Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade nginxUpgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade nginx-coreUpgrade nginx-light (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade nginx-fullUpgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade nginx-extras | Apr 28, 2026 | Apr 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 18, 2026 | Mar 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub