PT-2026-40655 · F5+4 · Nginx Plus+5

Published

2026-05-13

·

Updated

2026-06-23

·

CVE-2026-40701

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NGINX Plus (affected versions not specified) NGINX Open Source (affected versions not specified)
Description A heap-use-after-free error exists in the ngx http ssl module module. This occurs when the ssl verify client directive is set to "on" or "optional," and the ssl ocsp directive is set to "on" or the leaf parameters are configured with a resolver. An unauthenticated attacker can send requests that trigger this condition, potentially leading to limited data modification or the restarting of the NGINX worker process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06961
BIT-NGINX-2026-40701
BIT-NGINX-GATEWAY-2026-40701
CVE-2026-40701
ECHO-CBFE-5521-46AA
OPENSUSE-SU-2026:10796-1
SUSE-SU-2026:2370-1
USN-8354-1
USN-8375-1

Affected Products

Linuxmint
Nginx Open Source
Nginx Plus
Nginx
Red Os
Ubuntu