NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built with the ngx_mail_smtp_module, (2) the smtp_auth directive is configured with method "none," and (3) the authentication server returns the "Auth-Wait" response header.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Feb 6, 2026 | Aug 13, 2025 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-develUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-streamUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-all-modulesUpgrade nginx-coreUpgrade nginx-filesystemUpgrade nginxUpgrade nginx-mod-mailUpgrade nginx-mod-http-geoip | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-mod-streamUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-debugsourceUpgrade nginx-coreUpgrade nginx-mod-http-perlUpgrade nginx-mod-develUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-filesystemUpgrade nginx-core-debuginfo | Aug 19, 2025 | Aug 13, 2025 |
| Debian | — | Upgrade nginx | Sep 8, 2025 | Sep 8, 2025 |
| Freebsd | — | Upgrade nginx-devel | Dec 10, 2025 | Aug 15, 2025 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.29.1 | Aug 14, 2025 | Aug 13, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Aug 13, 2025 |
| Suse | — | Upgrade nginxUpgrade nginx-source | Dec 5, 2025 | Sep 5, 2025 |
| Ubuntu | — | Upgrade nginx-naxsi (Ubuntu Pro)Upgrade nginx-fullUpgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade nginx-core (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade nginx-extrasUpgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade nginxUpgrade nginx-light (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade nginx-coreUpgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade libnginx-mod-http-cache-purge (Ubuntu Pro) | Aug 26, 2025 | Aug 15, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 20, 2025 | Aug 13, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub