← Back

CVE-2026-28755

nvd nist
Published: Mar 24, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f5sirt@f5.com (Secondary)

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected (14)

2 products
Nginx Plus
Nginx Open Source
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version r33
Version r33 p1
Version r33 p2
Version r33 p3
Version r34
Version r34 p1
Version r34 p2
Version r35 p1
Version r36
Version r36 p1
Version r36 p2
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 0.5.13 to 0.9.7
From 1.27.2 to 1.28.3
From 1.29.0 to 1.29.7

References (1)

Source: f5sirt@f5.com
MitigationVendor Advisory

Timeline

No history available yet.