CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.7. It affects Nginx.
CVE
CVE-2026-28753
Severity
LOW
CVSS
3.7
EPSS
0.26%
Nginx
Original NVD Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Related CVEs
Other vulnerabilities affecting the same vendor(s)