NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built with the ngx_mail_smtp_module, (2) the smtp_auth directive is configured with method "none," and (3) the authentication server returns the "Auth-Wait" response header.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Feb 6, 2026 | Aug 13, 2025 |
| Amazon Linux Ami 2 | — | Upgrade nginx-coreUpgrade nginx-filesystemUpgrade nginx-mod-http-geoipUpgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginxUpgrade nginx-mod-develUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-image-filter | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-debuginfoUpgrade nginx-coreUpgrade nginx-mod-streamUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-develUpgrade nginx-debugsourceUpgrade nginx-mod-http-image-filterUpgrade nginx-core-debuginfoUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-mod-mail-debuginfoUpgrade nginx-all-modulesUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-filesystemUpgrade nginx-mod-mail | Aug 19, 2025 | Aug 13, 2025 |
| Debian | — | Upgrade nginx | Sep 8, 2025 | Sep 8, 2025 |
| Freebsd | — | Upgrade nginx-devel | Dec 10, 2025 | Aug 15, 2025 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.29.1 | Aug 14, 2025 | Aug 13, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Aug 13, 2025 |
| Suse | — | Upgrade nginxUpgrade nginx-source | Dec 5, 2025 | Sep 5, 2025 |
| Ubuntu | — | Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade nginx-extrasUpgrade nginx-core (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade nginx-fullUpgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro)Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade nginx-coreUpgrade nginx (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade nginx | Aug 26, 2025 | Aug 15, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 20, 2025 | Aug 13, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub