CVE-2026-28755: NGINX ngx_stream_ssl_module vulnerability
NGINX ngxstreamsslmodule vulnerability
Other sources
NGINX Plus and NGINX Open Source have a vulnerability in the ngxstreamsslmodule module due to the improper handling of revoked certificates when configured with the sslverifyclient on and sslocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28755?
CVE-2026-28755 has been assigned a high severity rating due to the potential risk of SSL certificate validation failures.
How do I fix CVE-2026-28755?
To fix CVE-2026-28755, upgrade NGINX Plus to version 33 or NGINX Open Source to version 1.29.6 or later.
What is the impact of CVE-2026-28755?
CVE-2026-28755 allows TLS handshakes to succeed even with revoked certificates, potentially enabling unauthorized access.
Which versions of NGINX are affected by CVE-2026-28755?
CVE-2026-28755 affects all versions of NGINX Plus and NGINX Open Source prior to the specified fixed versions.
Does CVE-2026-28755 affect both NGINX Open Source and NGINX Plus?
Yes, CVE-2026-28755 impacts both NGINX Open Source and NGINX Plus configurations.