BIT-nginx-2026-28755

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/nginx/BIT-nginx-2026-28755.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-nginx-2026-28755
Aliases
Published
2026-03-27T07:10:13.976Z
Modified
2026-03-27T08:56:24.461760Z
Summary
NGINX ngx_stream_ssl_module vulnerability
Details

NGINX Plus and NGINX Open Source have a vulnerability in the ngxstreamsslmodule module due to the improper handling of revoked certificates when configured with the sslverifyclient on and sslocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.  

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Database specific
{
    "cpes": [
        "cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / nginx

Package

Name
nginx
Purl
pkg:bitnami/nginx

Severity

  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.27.2
Fixed
1.28.3
Introduced
1.29.0
Fixed
1.29.7

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/nginx/BIT-nginx-2026-28755.json"