CVE-2026-28753 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in the ngx_mail_smtp_module of NGINX Plus (R32 to R36) and NGINX Open Source (1.0.0 to 1.29.6) due to improper handling of CRLF sequences in DNS responses. This flaw enables an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, potentially leading to request manipulation. Exploitation of this vulnerability could allow for unauthorized modification of SMTP requests sent upstream.
To address this vulnerability, users should upgrade to NGINX Plus R36 P3, R35 P2, or R32 P5. For NGINX Open Source users, the recommended versions are 1.29.7 or 1.28.3. Additionally, it is advised to use only trusted DNS resolvers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000160367 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx plus | r32 p1 r32 p2 r32 p3 r32 p4 r33 r33 p1 r33 p2 r33 p3 r34 r34 p1 r34 p2 r35 r35 p1 r36 r36 p1 r36 p2 |
CPE
Remediation
| |
| f5 nginx open source | >= 0.6.27, <= 0.9.7 >= 1.0.0, < 1.28.3 >= 1.29.0, < 1.29.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |