VDB

DEBIAN-CVE-2026-28753

DEBIAN-CVE-2026-28753 PUBLISHED CVSS 3.700000047683716 LOW

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Risk Scores

CVSS v3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Debian:11nginx1.30.0-1, 1.18.0-6.1, 1.18.0-6.1+deb11u1
Debian:14nginx0, 1.26.3-3, 1.28.0-1
Debian:12nginx1.28.1-1, 1.28.0-2, *
Debian:13nginx0, 1.28.0-1, 1.28.0-2

Timeline

  • Mar 24, 2026 CVE Published
  • May 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›