NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | May 15, 2026 | May 13, 2026 |
| Amazon Linux Ami 2 | — | Upgrade nginx-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-develUpgrade nginx-mod-http-xslt-filterUpgrade nginx-coreUpgrade nginx-mod-streamUpgrade nginx-mod-http-perlUpgrade nginx-filesystemUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-mod-http-geoipUpgrade nginx-all-modules | Jun 8, 2026 | Jun 8, 2026 |
| Amazon_linux_2023 | — | Upgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginx-core-debuginfoUpgrade nginx-mod-develUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-stream-debuginfoUpgrade nginx-debugsourceUpgrade nginx-debuginfoUpgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-mailUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginxUpgrade nginx-coreUpgrade nginx-mod-http-image-filter | May 28, 2026 | May 13, 2026 |
| Debian | — | Upgrade nginx | May 17, 2026 | May 17, 2026 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | May 21, 2026 | May 19, 2026 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Aug 17, 2026 | Aug 17, 2026 |
| Nginx | — | Upgrade to nginx version 1.31.0Upgrade to nginx version 1.30.1 | May 14, 2026 | May 13, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 13, 2026 |
| Ubuntu | — | Upgrade nginx-core (Ubuntu Pro)Upgrade libnginx-mod-http-xslt-filter (Ubuntu Pro)Upgrade libnginx-mod-mail (Ubuntu Pro)Upgrade nginx-common (Ubuntu Pro)Upgrade libnginx-mod-http-uploadprogress (Ubuntu Pro)Upgrade nginx-lightUpgrade nginx-coreUpgrade libnginx-mod-rtmp (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginxUpgrade libnginx-mod-http-lua (Ubuntu Pro)Upgrade libnginx-mod-http-headers-more-filter (Ubuntu Pro)Upgrade nginx-extras (Ubuntu Pro)Upgrade nginx (Ubuntu Pro)Upgrade nginx-naxsi (Ubuntu Pro)Upgrade libnginx-mod-http-cache-purge (Ubuntu Pro)Upgrade libnginx-mod-http-auth-pam (Ubuntu Pro)Upgrade libnginx-mod-http-dav-ext (Ubuntu Pro)Upgrade libnginx-mod-stream (Ubuntu Pro)Upgrade libnginx-mod-http-image-filter (Ubuntu Pro)Upgrade libnginx-mod-http-subs-filter (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade libnginx-mod-http-geoip (Ubuntu Pro)Upgrade libnginx-mod-http-ndk (Ubuntu Pro)Upgrade libnginx-mod-http-perl (Ubuntu Pro)Upgrade libnginx-mod-nchan (Ubuntu Pro)Upgrade nginx-extrasUpgrade nginx-fullUpgrade libnginx-mod-http-upstream-fair (Ubuntu Pro)Upgrade libnginx-mod-http-echo (Ubuntu Pro)Upgrade libnginx-mod-http-fancyindex (Ubuntu Pro) | Jun 2, 2026 | Jun 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub