Heap-Use-After-Free Vulnerability in NGINX Products
CVE-2026-40701

6.3MEDIUM

Key Information:

Vendor

F5

Vendor
CVE Published:
13 May 2026

What is CVE-2026-40701?

A vulnerability exists in the ngx_http_ssl_module of NGINX Plus and NGINX Open Source when the ssl_verify_client directive is enabled and the ssl_ocsp directive is active or configured with a resolver. This can be exploited by an unauthenticated attacker to trigger a heap-use-after-free condition in the NGINX worker process, potentially leading to limited data modification or unexpected process restarts.

Affected Version(s)

NGINX Open Source 1.19.0 < 1.30.1

NGINX Plus R36

NGINX Plus R32

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5 acknowledges Zhenpeng (Leo) Lin of depthfirst for bringing this issue to our attention and following the highest standards of coordinated disclosure.
.