CVE-2026-27651: F5 Nginx Open Source

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 Nginx Open Source: from 0.5.15, up to and including 0.9.7; from 1.0.0, before 1.28.3 (fixed in 1.28.3); from 1.29.0, before 1.29.7 (fixed in 1.29.7)
  • F5 Nginx Plus: from r33, before r35 (fixed in r35); version r32 only; version r35 only; version r36 only

Published 2026-03-24. Last modified 2026-07-15.