CVE-2026-28755
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
24/03/2026
Last modified:
26/03/2026
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked. <br />
<br />
<br />
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:* | ||
| cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* | 0.5.13 (including) | 0.9.7 (including) |
| cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* | 1.27.2 (including) | 1.28.3 (excluding) |
| cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* | 1.29.0 (including) | 1.29.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



