{"id":"CVE-2026-40701","title":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to \"on\" or \"optional,\" and the ssl_ocsp directive is set to \"on\" or the leaf parameters are configured wi…","summary":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to \"on\" or \"optional,\" and the ssl_ocsp directive is set to \"on\" or the leaf parameters are configured wi…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","cwe":["CWE-416"],"published":"2026-05-13","updated":"2026-06-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-40701","references":[{"url":"https://my.f5.com/manage/s/article/K000161021","label":"f5sirt@f5.com"}],"tags":["nvd","exploit-available"],"epss":0.0069,"epssPercentile":0.50955,"ingestedAt":"2026-06-29T13:24:34.845Z","exploits":{"github":1,"githubRepos":["https://github.com/edgecases-PurpleHax/cve-images"],"checkedAt":"2026-09-21T15:28:50.304Z"},"exploitAvailable":true,"slug":"CVE-2026-40701","body":"## Overview\n\nNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to \"on\" or \"optional,\" and the ssl_ocsp directive is set to \"on\" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or the NGINX worker process restarting.\n\n\n\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":26.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5177,"id":"CVE-2026-40701","ts":1788887251622,"field":"exploit_available","old":"false","new":"true"},{"seq":4060,"id":"CVE-2026-40701","ts":1788886367573,"field":"exploit_available","old":"true","new":"false"},{"seq":2851,"id":"CVE-2026-40701","ts":1788883034170,"field":"exploit_available","old":"false","new":"true"},{"seq":1880,"id":"CVE-2026-40701","ts":1788882437081,"field":"exploit_available","old":"true","new":"false"},{"seq":977,"id":"CVE-2026-40701","ts":1788881871369,"field":"exploit_available","old":"false","new":"true"}]}