Linuxsecurity
Critical Memory Disclosure Vulnerability in Nginx CVE-2025-53859
First seen 3 Jan 2026, 09:37 UTC
•
•39.3
Export
Article Content
Browse articles
A critical memory disclosure vulnerability (CVE-2025-53859) has been identified in Nginx's ngx_mail_smtp_module, affecting the processing of specially crafted login/password combinations using the 'none' authentication method. This issue may lead to memory disclosure to the authentication server. The vulnerability was addressed in the nginx 1.28.1 update released on December 23, 2025.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Fedora Skopeo Security Fix for CVE-2025-58189 and CVE-2025-61725
Critical CVE-2026-11332 Affects Fedora Ansible-Core Versions
Critical Buffer Overflow Vulnerability in pyOpenSSL Requires Immediate Action
Fedora Coturn Security Bypass Vulnerabilities Addressed in Recent Updates
Multiple Fedora Rust Packages Vulnerable to libgit2 Security Flaws
Oracle Linux Kernel ptrace Vulnerability CVE-2026-46333 Disclosed