This article provides a security assessment for CVE-2026-45447 regarding the compat-openssl11 package within the VMware NSX Container Plugin (NCP) environment. It addresses concerns raised by security scanners such as Nessus.
VMware NSX Container Plugin (NCP) 4.2.4.0
Analysis of the NSX Container Plugin (NCP) architecture confirms there is no viable attack vector for CVE-2026-45447.
- NCP exclusively connects to the Kubernetes API server and the NSX Manager using TLS.
- TLS negotiations rely on standard X.509 format certificates. While X.509 certificates can be stored in PKCS#7 formats, standard TLS libraries do not use or negotiate raw PKCS#7 or S/MIME messages during the handshake.
- NCP does not feed any post-termination TLS payload into the OpenSSL PKCS7_verify() function.
- As this is a VCF product, please note that fixed openssl and compat-openssl11 packages are planned for integration in future NCP releases. To be notified when this article is updated with specific release versions, please subscribe to this article.
For further details on the upstream vulnerability, refer to the Red Hat Errata:
RHEL 8: RHSA-2026:26275
RHEL 9: RHSA-2026:25239
If you still have any further queries, please reach out to Broadcom Support.