PT-2026-40655 · F5+1 · Nginx Open Source+2

Published

2026-05-13

·

Updated

2026-05-15

·

CVE-2026-40701

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions NGINX Plus (affected versions not specified) NGINX Open Source (affected versions not specified)
Description A heap-use-after-free error exists in the ngx http ssl module module. This occurs when the ssl verify client directive is set to "on" or "optional," and the ssl ocsp directive is set to "on" or the leaf parameters are configured with a resolver. An unauthenticated attacker can send requests that trigger this condition, potentially leading to limited data modification or the restarting of the NGINX worker process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

BIT-NGINX-2026-40701
BIT-NGINX-GATEWAY-2026-40701
CVE-2026-40701

Affected Products

Nginx Open Source
Nginx Plus
Nginx