Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-28755

Опубликовано: 24 мар. 2026
Источник: debian
EPSS Низкий

Описание

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nginxfixed1.28.3-2package
nginxnot-affectedtrixiepackage
nginxnot-affectedbookwormpackage
nginxnot-affectedbullseyepackage

Примечания

  • https://my.f5.com/manage/s/article/K000160368

  • Introduced with: https://github.com/nginx/nginx/commit/581cf22673fc63e206693294161ea32e691a432f (release-1.27.2)

  • Fixed by: https://github.com/nginx/nginx/commit/78f581487706f2e43eea5a060c516fc4d98090e8 (release-1.28.3)

EPSS

Процентиль: 3%
0.00133
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.4
redhat
4 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.4
nvd
4 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 5.4
msrc
4 месяца назад

NGINX ngx_stream_ssl_module vulnerability

CVSS3: 5.4
github
4 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 3%
0.00133
Низкий