CVE-2026-28755

MEDIUM EPSS 3.2%
Published Mar 24, 20263mo ago · Modified Jun 17, 20261w ago
5.3 CVSS 4.0
Medium
Find Similar
Published Mar 24, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Details

Base Score
5.3
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
3.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-863 Incorrect Authorization Authorization

Affected Products 14

VendorProductVersionRange
f5nginx_plusr33any
f5nginx_plusr33any
f5nginx_plusr33any
f5nginx_plusr33any
f5nginx_plusr34any
f5nginx_plusr34any
f5nginx_plusr34any
f5nginx_plusr35any
f5nginx_plusr36any
f5nginx_plusr36any
f5nginx_plusr36any
f5nginx_open_source*≥0.5.13  –  ≤0.9.7
f5nginx_open_source*≥1.27.2  –  <1.28.3
f5nginx_open_source*≥1.29.0  –  <1.29.7

References 1

  • my.f5.com https://my.f5.com/manage/s/article/K000160368
    MitigationVendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.