Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40701

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

A flaw was found in the ngx_http_ssl_module module of NGINX. When the ssl_verify_client directive is set to "on" or "optional" and the ssl_ocsp directive is enabled or its leaf parameters are configured with a resolver, an unauthenticated attacker can send crafted requests to cause a use-after-free issue in the worker process, resulting in a limited modification of memory data or a denial of service by forcing the process to restart.

Отчет

To exploit this flaw, the ssl_verify_client directive must be set to "on" or "optional" and the ssl_ocsp directive must be enabled or its leaf parameters configured with a resolver, limiting its exposure as this is not the default configuration. This issue allows an attacker to have limited control to modify memory data from the worker process or cause a denial of service by forcing the process to restart, but it cannot cause a complete system denial of service. Due to these reasons, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this issue, specifically set the OCSP responder using the ssl_ocsp_responder directive or switch from live OCSP validation to static CRL files using the ssl_crl directive. If neither configuration is possible, using a local DNS server to cache and quickly resolve OCSP responder names can reduce the probability of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nginxFix deferred
Red Hat Enterprise Linux 8nginx:1.24/nginxFix deferred
Red Hat Enterprise Linux 9nginxFix deferred
Red Hat Enterprise Linux 9nginx:1.24/nginxOut of support scope
Red Hat Enterprise Linux 9nginx:1.26/nginxFix deferred
Red Hat Hardened ImagesnginxNot affected
Red Hat Lightspeed proxy 1insights-proxy/insights-proxy-container-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2477076nginx: ngx_http_ssl_module: data corruption and denial of service

EPSS

Процентиль: 49%
0.00677
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
nvd
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 4.8
msrc
3 месяца назад

NGINX ngx_http_ssl_module vulnerability

CVSS3: 4.8
debian
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ ...

CVSS3: 4.8
github
3 месяца назад

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 49%
0.00677
Низкий

4.8 Medium

CVSS3