---
schema_version: '1.0'
id: security-20260705-aa44e8
url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-28755
url_hash: aa44e87ef41491c4b96f9af835c326f79c513c4ab369452172b55a29141eaeb7
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2026-28755
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2026-28755
- severity:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- nginx
- Debian
lang: en
published_at: '2026-03-24T15:16:33Z'
fetched_at: '2026-07-05T15:34:33Z'
updated_at: '2026-07-05T15:34:52Z'
status: published
content_hash: 7b79b63229a7e7c2a10d911743188bb32cb816cc404e3944dd801aa993e1dba3
license_note: full
summary: 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module
  module due to the improper handling of revoked certificates when configured with
  the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake
  to succeed even after an OCSP check '
summary_source: rss
summary_en: 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module
  module due to the improper handling of revoked certificates when configured with
  the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake
  to succeed even after an OCSP check '
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2026-28755 — nginx
---

# DEBIAN-CVE-2026-28755 — nginx

## TL;DR
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check 

## Key Points
- cve / DEBIAN-CVE-2026-28755 / severity:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N / nginx / Debian

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
**Advisory:** DEBIAN-CVE-2026-28755

**Affected (your watchlist):**
- `Debian:nginx` 1.22.1-9+deb12u1 → no fixed version listed [proxmox]

**Details:**
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2026-28755

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2026-28755_

## Source
元記事: [DEBIAN-CVE-2026-28755 — nginx](https://osv.dev/vulnerability/DEBIAN-CVE-2026-28755) — published 2026-03-24T15:16:33Z
