CVE-2026-28755: F5 Nginx Open Source

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 Nginx Open Source: from 0.5.13, up to and including 0.9.7; from 1.27.2, before 1.28.3 (fixed in 1.28.3); from 1.29.0, before 1.29.7 (fixed in 1.29.7)
  • F5 Nginx Plus: version r33 only; version r34 only; version r35 only; version r36 only

Published 2026-03-24. Last modified 2026-06-17.