Critical Memory Disclosure Vulnerability in Nginx CVE-2025-53859

Critical Memory Disclosure Vulnerability in Nginx CVE-2025-53859

First seen 3 Jan 2026, 09:37 UTC Linuxsecurity 39.3

Article Content

Browse articles
ThreatCluster

A critical memory disclosure vulnerability (CVE-2025-53859) has been identified in Nginx's ngx_mail_smtp_module, affecting the processing of specially crafted login/password combinations using the 'none' authentication method. This issue may lead to memory disclosure to the authentication server. The vulnerability was addressed in the nginx 1.28.1 update released on December 23, 2025.