CVE-2026-40701 Details
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A heap-use-after-free vulnerability has been identified in the ngx_http_ssl_module of NGINX Plus and NGINX Open Source. This issue arises when the ssl_verify_client directive is set to 'on' or 'optional', and the ssl_ocsp directive is enabled or the leaf parameters are configured with a resolver. Under these conditions, an unauthenticated attacker can send requests that trigger the vulnerability, potentially leading to a heap-use-after-free error in the NGINX worker process. The consequence of this vulnerability may include limited data modification or a restart of the NGINX worker process.
To address this vulnerability, users can update to NGINX versions 1.31.0 or 1.30.1 for NGINX Open Source, or versions R36 P4 or R32 P6 for NGINX Plus. For NGINX Instance Manager, versions 2.21.1 and 2.16.0 should be avoided. If using NGINX App Protect WAF, versions 5.9.0 to 5.12.1 and 4.9.0 to 4.16.0 are vulnerable. In NGINX Gateway Fabric, versions 2.0.0 to 2.5.1 and 1.3.0 to 1.6.2 should be updated. For NGINX Ingress Controller, versions 5.0.0 to 5.4.1, 4.0.0 to 4.0.1, and 3.5.0 to 3.7.2 are affected. Users can also mitigate the vulnerability by specifying an OCSP responder using the ssl_ocsp_responder directive, or by switching from OCSP to CRL files using the ssl_crl directive.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161021 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 dos | >= 4.3.0, <= 4.7.0 4.8.0 |
CPE
Remediation
| |
| f5 nginx gateway fabric | >= 1.3.0, <= 1.6.2 >= 2.0.0, <= 2.6.0 |
CPE
Remediation
| |
| f5 nginx ingress controller | >= 3.5.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, <= 5.4.2 |
CPE
Remediation
| |
| f5 nginx instance manager | >= 2.16.0, <= 2.22.0 |
CPE
Remediation
| |
| f5 nginx open source | >= 1.19.0, <= 1.30.0 |
CPE
Remediation
| |
| f5 nginx plus | >= r32, <= r36 |
CPE
Remediation
| |
| f5 waf | >= 4.9.0, <= 4.16.0 >= 5.1.0, <= 5.8.0 >= 5.9.0, <= 5.12.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |