CVE-2026-28755 PUBLISHED

NGINX ngx_stream_ssl_module vulnerability

Assigner: f5
Reserved: 18.03.2026 Published: 24.03.2026 Updated: 24.03.2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.  

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor F5
Product NGINX Open Source
Versions Default: unknown
  • affected from 1.29.0 to 1.29.7 (excl.)
  • affected from 1.27.2 to 1.28.3 (excl.)
Vendor F5
Product NGINX Plus
Versions Default: unknown
  • affected from R36 to R36 P3 (excl.)
  • affected from R35 to R35 P2 (excl.)
  • affected from R34 to * (excl.)
  • affected from R33 to * (excl.)

Credits

  • Mufeed VH of Winfunc Research reporter

References

Problem Types

  • CWE-863 Incorrect Authorization CWE