CVE-2026-28755

Published Mar 24, 2026

Last updated 5 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-28755 describes a vulnerability found in NGINX, specifically within its `ngx_stream_ssl_module`. This flaw occurs when NGINX is configured to verify client certificates and utilize the Online Certificate Status Protocol (OCSP) for revocation checks. The vulnerability allows a Transport Layer Security (TLS) handshake to successfully complete even if the client's certificate has been identified as revoked by an OCSP check. This improper handling of revoked certificates means that certificate revocation validation can be bypassed.

Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source
f5sirt@f5.com
NVD status
Analyzed
Products
nginx_plus, nginx_open_source

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
5.4
Impact score
2.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

f5sirt@f5.com
CWE-863

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.