Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-06961

Опубликовано: 13 мая 2026
Источник: fstec
CVSS3: 4.8
CVSS2: 4
EPSS Низкий

Описание

Уязвимость модуля ngx_http_ssl_module веб-серверов NGINX Plus и NGINX Open Source связана с использованием памяти после освобождения. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, оказать воздействие на конфиденциальность и доступность защищаемой информации

Вендор

ООО «Ред Софт»
АО «ИВК»
NGINX Inc.
ООО "Веб-Сервер"

Наименование ПО

РЕД ОС
Альт 8 СП
АЛЬТ СП 10
NGINX Plus
NGINX Instance Manager
F5 WAF for NGINX
NGINX App Protect WAF
F5 DoS for NGINX
NGINX App Protect DoS
NGINX Gateway Fabric
NGINX Ingress Controller
NGINX Open Source
Angie
Angie PRO

Версия ПО

7.3 (РЕД ОС)
- (Альт 8 СП)
- (АЛЬТ СП 10)
8.0 (РЕД ОС)
от R32 до R36 P4 (NGINX Plus)
от R32 до R32 P6 (NGINX Plus)
от 2.16.0 до 2.21.1 включительно (NGINX Instance Manager)
от 5.9.0 до 5.12.1 включительно (F5 WAF for NGINX)
от 5.1.0 до 5.8.0 включительно (NGINX App Protect WAF)
от 4.9.0 до 4.16.0 включительно (NGINX App Protect WAF)
4.8.0 (F5 DoS for NGINX)
от 4.3.0 до 4.7.0 включительно (NGINX App Protect DoS)
от 2.0.0 до 2.5.1 включительно (NGINX Gateway Fabric)
от 1.3.0 до 1.6.2 включительно (NGINX Gateway Fabric)
от 5.0.0 до 5.4.1 включительно (NGINX Ingress Controller)
от 4.0.0 до 4.0.1 включительно (NGINX Ingress Controller)
от 3.5.0 до 3.7.2 включительно (NGINX Ingress Controller)
от 1.19.0 до 1.31.0 (NGINX Open Source)
от 1.19.0 до 1.30.1 (NGINX Open Source)
до 1.11.5 (Angie)
до 1.11.5 (Angie PRO)

Тип ПО

Операционная система
Сетевое средство
Программное средство защиты
Прикладное ПО информационных систем
Сетевое программное средство

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
АО «ИВК» Альт 8 СП -
АО «ИВК» АЛЬТ СП 10 -
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 4,8)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://my.f5.com/manage/s/article/K000161021
Для Angie:
https://angie.software/angie/docs/oss_changes/
Для Angie PRO:
https://angie.software/angie/docs/pro_changes/
Для ОС АЛЬТ СП 10: установка обновления из публичного репозитория программного средства: https://altsp.su/obnovleniya-bezopasnosti/
Для ОС Альт 8 СП: установка обновления из публичного репозитория программного средства: https://altsp.su/obnovleniya-bezopasnosti/
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-40701

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 48%
0.00677
Низкий

4.8 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.8
redos
около 1 месяца назад

Уязвимость angie

CVSS3: 4.8
redos
около 2 месяцев назад

Уязвимость nginx

CVSS3: 4.8
ubuntu
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
redhat
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
nvd
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 48%
0.00677
Низкий

4.8 Medium

CVSS3

4 Medium

CVSS2