#VU124473 NULL pointer dereference in NGINX Open Source and NGINX Plus - CVE-2026-27651
Published: March 25, 2026
NGINX Open Source
NGINX Plus
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the ngx_mail_auth_http_module module. A remote attacker can send specially crafted request to the server and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that the CRAM-MD5 or APOP authentication is enabled, and the authentication server permits retry by returning the Auth-Wait response header.