Логотип exploitDog
bind:"BDU:2026-04820" OR bind:"CVE-2026-27651"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2026-04820" OR bind:"CVE-2026-27651"

Количество 16

Количество 16

fstec логотип

BDU:2026-04820

около 1 месяца назад

Уязвимость модуля ngx_mail_auth_http_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-27651

около 1 месяца назад

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-27651

около 1 месяца назад

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-27651

около 1 месяца назад

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-27651

около 1 месяца назад

NGINX ngx_mail_auth_http_module vulnerability

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-27651

около 1 месяца назад

When the ngx_mail_auth_http_modulemodule is enabled on NGINX Plus or N ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-82w2-x7hf-5h8r

около 1 месяца назад

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:7343

27 дней назад

Important: nginx:1.26 security update

EPSS: Низкий
rocky логотип

RLSA-2026:6923

29 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:6907

27 дней назад

Important: nginx:1.24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:6906

27 дней назад

Important: nginx security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7343

26 дней назад

ELSA-2026-7343: nginx:1.26 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-7002

29 дней назад

ELSA-2026-7002: nginx security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6923

29 дней назад

ELSA-2026-6923: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6907

29 дней назад

ELSA-2026-6907: nginx:1.24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-6906

30 дней назад

ELSA-2026-6906: nginx security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-04820

Уязвимость модуля ngx_mail_auth_http_module HTTP-сервера NGINX Plus и NGINX Open Source, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-27651

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-27651

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-27651

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-27651

NGINX ngx_mail_auth_http_module vulnerability

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-27651

When the ngx_mail_auth_http_modulemodule is enabled on NGINX Plus or N ...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-82w2-x7hf-5h8r

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:7343

Important: nginx:1.26 security update

27 дней назад
rocky логотип
RLSA-2026:6923

Important: nginx:1.24 security update

29 дней назад
rocky логотип
RLSA-2026:6907

Important: nginx:1.24 security update

27 дней назад
rocky логотип
RLSA-2026:6906

Important: nginx security update

27 дней назад
oracle-oval логотип
ELSA-2026-7343

ELSA-2026-7343: nginx:1.26 security update (IMPORTANT)

26 дней назад
oracle-oval логотип
ELSA-2026-7002

ELSA-2026-7002: nginx security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-6923

ELSA-2026-6923: nginx:1.24 security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-6907

ELSA-2026-6907: nginx:1.24 security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-6906

ELSA-2026-6906: nginx security update (IMPORTANT)

30 дней назад

Уязвимостей на страницу