Skip to content

CVE-2026-28755 #2047

Description

@tengxiao

Ⅰ. Issue Description

CVE-2026-28755
ngx_stream_ssl_module 模块。该漏洞允许攻击者在使用已吊销证书的情况下,仍成功建立 TLS 连接,从而绕过基于 OCSP(在线证书状态协议)的客户端证书验证机制

Ⅱ. Describe what happened

Ⅲ. Describe what you expected to happen

Ⅳ. How to reproduce it (as minimally and precisely as possible)

Ⅴ. Anything else we need to know?

  1. If applicable, add nginx debug log doc.

Ⅵ. Environment:

  • Tengine version (use sbin/nginx -V):
  • OS (e.g. from /etc/os-release):
  • Kernel (e.g. uname -a):
  • Others:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions