Skip to content
Critical Memory Disclosure Vulnerability in Nginx CVE-2025-53859

Critical Memory Disclosure Vulnerability in Nginx CVE-2025-53859

First seen 3 Jan 2026, 09:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A critical memory disclosure vulnerability (CVE-2025-53859) has been identified in Nginx's ngx_mail_smtp_module, affecting the processing of specially crafted login/password combinations using the 'none' authentication method. This issue may lead to memory disclosure to the authentication server. The vulnerability was addressed in the nginx 1.28.1 update released on December 23, 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (7)

Following this threat?

Track Fedora and CVE-2025-53859 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed