CVE-2026-28753
CVE-2026-28753 is a low-severity vulnerability in F5 Nginx Plus with a CVSS 3.x base score of 3.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-93.
Key facts
- Severity: Low (CVSS 3.x base score 3.7)
- CVSS v4: 6.3
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-14885
- Weakness: CWE-93
- Affected product: F5 Nginx Plus
- Published:
- Last modified:
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Frequently asked questions
- What is CVE-2026-28753?
- NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- How severe is CVE-2026-28753?
- CVE-2026-28753 has a CVSS 3.x base score of 3.7, rated low severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-28753 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-28753?
- CVE-2026-28753 primarily affects F5 Nginx Plus. In total, 17 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-28753?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-28753 have an EU (EUVD) identifier?
- Yes. CVE-2026-28753 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-14885.
- When was CVE-2026-28753 published?
- CVE-2026-28753 was published on 2026-03-24 and last updated on 2026-06-17.
References
Affected products (17)
- cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r35:*:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*
- cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*
More vulnerabilities in F5 Nginx Plus
- CVE-2026-60005 — High (CVSS 8.2): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive…
- CVE-2026-27654 — High (CVSS 8.2): NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to…
- CVE-2026-42533 — High (CVSS 8.1): A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string…
- CVE-2026-42055 — High (CVSS 8.1): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and…
- CVE-2026-9256 — High (CVSS 8.1): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists…
- CVE-2026-42945 — High (CVSS 8.1): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists…
All CVEs affecting F5 Nginx Plus →
Other CWE-93 (CRLF Injection) vulnerabilities
- CVE-2024-51501 — Critical (CVSS 10.0): Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit…
- CVE-2026-70615 — Critical (CVSS 9.9): boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users…
- CVE-2026-45372 — Critical (CVSS 9.9): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's…
- CVE-2026-72590 — Critical (CVSS 9.8): An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote…
- CVE-2026-11362 — Critical (CVSS 9.8): DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not…
- CVE-2025-40671 — Critical (CVSS 9.3): SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve,…