CVE-2026-28755: NGINX ngx_stream_ssl_module vulnerability

Published Mar 24, 2026
·
Updated

NGINX ngxstreamsslmodule vulnerability

Other sources

NGINX Plus and NGINX Open Source have a vulnerability in the ngxstreamsslmodule module due to the improper handling of revoked certificates when configured with the sslverifyclient on and sslocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.

F5

Affected Software

21 affected componentsFixes available
Nginx NGINX Open Source
Nginx NGINX Plus
F5 NGINX Plus=33
36
F5 NGINX Open Source>=1.27.2<=1.29.6
1.29.71.28.3
F5 NGINX Open Source>=0.5.13<=0.9.7
F5 NGINX Plus=r33
F5 NGINX Plus=r33-p1
F5 NGINX Plus=r33-p2
F5 NGINX Plus=r33-p3
F5 NGINX Plus=r34
F5 NGINX Plus=r34-p1
F5 NGINX Plus=r34-p2
F5 NGINX Plus=r35-p1
F5 NGINX Plus=r36
F5 NGINX Plus=r36-p1
F5 NGINX Plus=r36-p2
F5 NGINX Open Source>=0.5.13<=0.9.7
F5 NGINX Open Source>=1.27.2<1.28.3
F5 NGINX Open Source>=1.29.0<1.29.7
Microsoft azl3 nginx 1.28.2-1
Microsoft cbl2 nginx 1.22.1-15

Event History

Mar 24, 2026
Advisory Published
via F5·01:32 PM
Data Sourced
via F5·01:32 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 27, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Updated
via Microsoft·08:02 AM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-28755?

CVE-2026-28755 has been assigned a high severity rating due to the potential risk of SSL certificate validation failures.

2

How do I fix CVE-2026-28755?

To fix CVE-2026-28755, upgrade NGINX Plus to version 33 or NGINX Open Source to version 1.29.6 or later.

3

What is the impact of CVE-2026-28755?

CVE-2026-28755 allows TLS handshakes to succeed even with revoked certificates, potentially enabling unauthorized access.

4

Which versions of NGINX are affected by CVE-2026-28755?

CVE-2026-28755 affects all versions of NGINX Plus and NGINX Open Source prior to the specified fixed versions.

5

Does CVE-2026-28755 affect both NGINX Open Source and NGINX Plus?

Yes, CVE-2026-28755 impacts both NGINX Open Source and NGINX Plus configurations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203