CVE-2026-40701
published 2026-05-13CVE-2026-40701: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and…
PriorityP429medium4.8CVSS 3.1
AVNACHPRNUINSUCLINAL
EPSS
0.68%
48.2th percentile
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | dos | — | — |
| f5 | dos | 4.3.0 – 4.7.0 | — |
| f5 | nginx_gateway_fabric | 1.3.0 – 1.6.2 | — |
| f5 | nginx_gateway_fabric | 2.0.0 – 2.6.0 | — |
| f5 | nginx_ingress_controller | 3.5.0 – 3.7.2 | — |
| f5 | nginx_ingress_controller | 4.0.0 – 4.0.1 | — |
| f5 | nginx_ingress_controller | 5.0.0 – 5.4.2 | — |
| f5 | nginx_instance_manager | 2.16.0 – 2.22.0 | — |
| f5 | nginx_open_source | >= 1.19.0 < 1.30.1 | 1.30.1 |
| f5 | nginx_open_source | 1.19.0 – 1.30.0 | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R32 < R32 P6 | R32 P6 |
| f5 | nginx_plus | >= R36 < R36 P4 | R36 P4 |
| f5 | nginx_plus | r32 – r36 | — |
| f5 | waf | 4.9.0 – 4.16.0 | — |
| f5 | waf | 5.1.0 – 5.8.0 | — |
| f5 | waf | 5.9.0 – 5.12.1 | — |
| insights-proxy | insights-proxy-container-rhel9 | — | — |
| nginx_1.24 | nginx | — | — |
| nginx_1.26 | nginx | — | — |
| ubuntu | nginx | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu6.9MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-03·CVSS 6.3
CVE-2026-1642 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that the nginx ngx_mail_smtp_module module incorrectly
handled certain memory operations when doing SMTP authentication. This
could possibly result in sensitive information being sent to the
authentication server. (CVE-2025-53859)
It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server. (CVE-2026-1642)
It was discovered that the nginx ngx_mail_auth_http_module module
incorrectly handled certain requests. An attacker could possibly use this
issue to cause nginx to crash, resulting in a denial of service.
(CVE-2026-27651)
It was discovered that
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2026-06-01·CVSS 6.9
CVE-2026-9256 [MEDIUM] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx did not properly validate source addresses in
the HTTP/3 QUIC module. A remote attacker could possibly use this issue to
bypass authorization checks or rate limiting. This issue only affected
Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-40460)
It was discovered that nginx contained a use-after-free vulnerability in
the ngx_http_ssl_module module when client certificate verification and
OCSP validation were enabled. A remote attacker could use this issue to
cause nginx to crash, resulting in a denial of service, or possibly modify
data in memory. (CVE-2026-40701)
It was discovered that nginx did not properly handle certain proxied
responses in the ngx_http_charset_module module. A
Red Hat
nginx: ngx_http_ssl_module: data corruption and denial of service
vendor_redhat·2026-05-13·CVSS 6.3
CVE-2026-40701 [MEDIUM] CWE-416 nginx: ngx_http_ssl_module: data corruption and denial of service
nginx: ngx_http_ssl_module: data corruption and denial of service
A flaw was found in the ngx_http_ssl_module module of NGINX. When the ssl_verify_client directive is set to "on" or "optional" and the ssl_ocsp directive is enabled or its leaf parameters are configured with a resolver, an unauthenticated attacker can send crafted requests to cause a use-after-free issue in the worker process, resulting in a limited modification of memory data or a denial of service by forcing the process to restart.
Statement: To exploit this flaw, the ssl_verify_client directive must be set to "on" or "optional" and the ssl_ocsp directive must be enabled or its leaf parameters configured with a resolver, limiting its exposure as this is not the default configuration. This issue allows an attacker to have
F5
CVE-2026-40701: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client di...
vendor_f5·2026-05-13·CVSS 6.3
CVE-2026-40701 [MEDIUM] CWE-416 CVE-2026-40701: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client di...
CVE-2026-40701: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client di...
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: NGINX Pl
GHSA
GHSA-x88q-x2r7-vg3g: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "option
ghsa_unreviewed·2026-05-13
CVE-2026-40701 [MEDIUM] CWE-416 GHSA-x88q-x2r7-vg3g: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "option
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40701 nginx: ngx_http_ssl_module: data corruption and denial of service
bugzilla·2026-05-13·CVSS 6.3
CVE-2026-40701 [MEDIUM] CVE-2026-40701 nginx: ngx_http_ssl_module: data corruption and denial of service
CVE-2026-40701 nginx: ngx_http_ssl_module: data corruption and denial of service
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Hackernews
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
blogs_hackernews·2026-05-14·CVSS 9.2
CVE-2026-42945 [CRITICAL] 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years.
The vulnerability, discovered by depthfirst , is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to achieve remote code execution or cause a denial-of-service (DoS) with crafted requests. It has been codenamed NGINX Rift .
"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_modul
2026-05-13
Published