Security · September 26, 2026
Vulnerability Discovered in NGINX HTTP/3 Module
A vulnerability has been revealed in the HTTP/3 implementation of the web server NGINX. An update is available to address this issue.
On September 15, 2026, F5 published a security advisory disclosing the vulnerability identified as CVE-2026-90439.
The vulnerability involves a heap-based buffer overflow occurring in the module that processes HTTP/3. If HTTP/3 is used with OpenSSL 3.5.0 or earlier versions under certain configurations, a limited heap buffer overflow may occur during the TLS handshake process, potentially leading to denial of service or limited data corruption.
The affected systems include the open-source version of NGINX, the commercial version NGINX Plus, as well as the NGINX Ingress Controller, NGINX Gateway Fabric, and NGINX Instance Manager.