CVE-2026-45447 vulnerability assessment for NSX Container Plugin
search cancel

CVE-2026-45447 vulnerability assessment for NSX Container Plugin

book

Article ID: 445816

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

This article provides a security assessment for CVE-2026-45447 regarding the compat-openssl11 package within the VMware NSX Container Plugin (NCP) environment. It addresses concerns raised by security scanners such as Nessus.

Environment

VMware NSX Container Plugin (NCP) 4.2.4.0

Resolution

Analysis of the NSX Container Plugin (NCP) architecture confirms there is no viable attack vector for CVE-2026-45447.

- NCP exclusively connects to the Kubernetes API server and the NSX Manager using TLS.
- TLS negotiations rely on standard X.509 format certificates. While X.509 certificates can be stored in PKCS#7 formats, standard TLS libraries do not use or negotiate raw PKCS#7 or S/MIME messages during the handshake.
- NCP does not feed any post-termination TLS payload into the OpenSSL PKCS7_verify() function.
- As this is a VCF product, please note that fixed openssl and compat-openssl11 packages are planned for integration in future NCP releases. To be notified when this article is updated with specific release versions, please subscribe to this article.

 

Additional Information

For further details on the upstream vulnerability, refer to the Red Hat Errata:

RHEL 8: RHSA-2026:26275
RHEL 9: RHSA-2026:25239

If you still have any further queries, please reach out to Broadcom Support.