Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 26 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r32:p2:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r32:p3:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r32:p4:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r35:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* |
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5
F5 nginx Open Source F5 nginx Plus |
|
| Vendors & Products |
F5
F5 nginx Open Source F5 nginx Plus |
Wed, 25 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 24 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
Tue, 24 Mar 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Title | NGINX ngx_mail_proxy_module vulnerability | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2026-03-24T15:24:34.995Z
Reserved: 2026-03-18T16:06:38.435Z
Link: CVE-2026-28753
Updated: 2026-03-24T15:24:31.847Z
Status : Analyzed
Published: 2026-03-24T15:16:33.560
Modified: 2026-03-26T21:15:24.053
Link: CVE-2026-28753
OpenCVE Enrichment
Updated: 2026-03-27T09:21:02Z