CVE-2026-28753: F5 Nginx Open Source
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 Nginx Open Source: from 0.6.27, up to and including 0.9.7; from 1.0.0, before 1.28.3 (fixed in 1.28.3); from 1.29.0, before 1.29.7 (fixed in 1.29.7)
- F5 Nginx Plus: version r32 only; version r33 only; version r34 only; version r35 only; version r36 only
Published 2026-03-24. Last modified 2026-06-17.