NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 5.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Mar 27, 2026 | Mar 24, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-filesystemUpgrade nginx-mod-streamUpgrade nginx-coreUpgrade nginx-debuginfoUpgrade nginx-mod-http-geoipUpgrade nginx-mod-http-perlUpgrade nginx-mod-develUpgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginx-mod-http-image-filterUpgrade nginx | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-filesystemUpgrade nginx-all-modulesUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-mod-mailUpgrade nginx-core-debuginfoUpgrade nginx-mod-develUpgrade nginx-mod-http-xslt-filterUpgrade nginx-coreUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-debugsourceUpgrade nginx-mod-streamUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-debuginfo | Apr 14, 2026 | Mar 24, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.29.7Upgrade to nginx version 1.28.3 | Mar 27, 2026 | Mar 24, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 24, 2026 |
| Ubuntu | — | Upgrade nginx-fullUpgrade nginxUpgrade nginx-coreUpgrade nginx-extrasUpgrade nginx-light | Apr 28, 2026 | Apr 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 18, 2026 | Mar 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub