Use-after-free in NGINX Open Source and NGINX Plus - CVE-2026-40701
Published: May 14, 2026
NGINX Open Source
NGINX Plus
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service or modify data in a limited manner.
The vulnerability exists due to use-after-free in ngx_http_ssl_module when handling requests with client certificate verification and OCSP checking enabled. A remote attacker can send requests that trigger the flaw to cause a denial of service or modify data in a limited manner.
This issue affects the data plane only. Exploitation requires the ssl_verify_client directive to be set to "on" or "optional," and the ssl_ocsp directive to be set to "on" or configured with the leaf parameter and a resolver.