CVE-2025-53859
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-13

Last updated on: 2025-11-04

Assigner: F5 Networks

Description
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built with the ngx_mail_smtp_module, (2) the smtp_auth directive is configured with method "none," and (3) the authentication server returns the "Auth-Wait" response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-13
Last Modified
2025-11-04
Generated
2026-05-27
AI Q&A
2025-08-13
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 11 associated CPEs
Vendor Product Version / Range
f5 nginx_plus r30
f5 nginx_plus r31
f5 nginx_plus r32
f5 nginx_plus r32
f5 nginx_plus r32
f5 nginx_plus r33
f5 nginx_plus r33
f5 nginx_plus r33
f5 nginx_plus r34
f5 nginx_plus r34
f5 nginx_open_source From 0.7.22 (inc) to 1.29.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in NGINX Open Source and NGINX Plus within the ngx_mail_smtp_module. It allows an unauthenticated attacker to over-read memory during the SMTP authentication process. Specifically, if NGINX is built with the ngx_mail_smtp_module, configured with smtp_auth method set to "none," and the authentication server returns the "Auth-Wait" response header, the attacker can cause the server to leak arbitrary bytes from its memory that were sent in a request to the authentication server. Exploiting this requires the attacker to prepare against the target system to extract the leaked data.


How can this vulnerability impact me? :

The impact of this vulnerability is that an attacker can obtain arbitrary bytes from the server's memory during the SMTP authentication process without authentication. This could lead to leakage of sensitive information that was sent in requests to the authentication server. However, exploitation requires specific conditions and preparation by the attacker. The CVSS v4.0 base score of 6.3 indicates a moderate severity with network attack vector and low complexity.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart