NGINX Plus and NGINX Open Source have a vulnerability in...
Moderate severity
Unreviewed
Published
Mar 24, 2026
to the GitHub Advisory Database
•
Updated Mar 24, 2026
Description
Published by the National Vulnerability Database
Mar 24, 2026
Published to the GitHub Advisory Database
Mar 24, 2026
Last updated
Mar 24, 2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References