LIVE · cybersecurity feed
Live wire
cve recordlow

CVE-2026-28753

f5 · nginx plus

Published
CVSS3.7
Severitylow
WeaknessCWE-93
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-28753

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-28753.