CVE-2026-27651: CWE-476 NULL Pointer Dereference in F5 NGINX Open Source
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AI Analysis
Technical Summary
CVE-2026-27651 is a denial of service vulnerability in F5 NGINX Open Source related to the ngx_mail_auth_http_module. When this module is enabled, and CRAM-MD5 or APOP authentication is used with an authentication server that permits retries via the Auth-Wait response header, specially crafted requests can cause worker processes to terminate due to a NULL pointer dereference (CWE-476). This vulnerability has a CVSS 3.1 base score of 7.5 (high severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts availability only. Red Hat has issued security advisories and updates for affected Red Hat Enterprise Linux versions to address this issue.
Potential Impact
The vulnerability causes denial of service by terminating NGINX worker processes when certain mail authentication configurations are used. This results in service disruption and reduced availability of the affected NGINX server. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released security updates for affected packages in Red Hat Enterprise Linux 10.0 Extended Update Support and other supported variants. Applying these official vendor updates will remediate the vulnerability. Users should refer to the Red Hat advisories (e.g., RHSA-2026:13634) for detailed update instructions. Since this is not a cloud service, remediation depends on applying these patches. Patch status is confirmed by vendor advisories. No alternative mitigations are specified.
CVE-2026-27651: CWE-476 NULL Pointer Dereference in F5 NGINX Open Source
Description
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-27651 is a denial of service vulnerability in F5 NGINX Open Source related to the ngx_mail_auth_http_module. When this module is enabled, and CRAM-MD5 or APOP authentication is used with an authentication server that permits retries via the Auth-Wait response header, specially crafted requests can cause worker processes to terminate due to a NULL pointer dereference (CWE-476). This vulnerability has a CVSS 3.1 base score of 7.5 (high severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts availability only. Red Hat has issued security advisories and updates for affected Red Hat Enterprise Linux versions to address this issue.
Potential Impact
The vulnerability causes denial of service by terminating NGINX worker processes when certain mail authentication configurations are used. This results in service disruption and reduced availability of the affected NGINX server. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released security updates for affected packages in Red Hat Enterprise Linux 10.0 Extended Update Support and other supported variants. Applying these official vendor updates will remediate the vulnerability. Users should refer to the Red Hat advisories (e.g., RHSA-2026:13634) for detailed update instructions. Since this is not a cloud service, remediation depends on applying these patches. Patch status is confirmed by vendor advisories. No alternative mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- f5
- Date Reserved
- 2026-03-18T16:06:38.454Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-27651","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13634","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6906","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6907","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:15942","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14836","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13839","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:15943","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:15945","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13680","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:15966","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6923","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7002","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7343","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8346","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10065","vendor":"Red Hat"}]
Threat ID: 69c2a3a3f4197a8e3b3ed938
Added to database: 03/24/2026, 14:45:55 UTC
Last enriched: 07/15/2026, 08:44:20 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 196
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.