Security · September 26, 2026

Vulnerability Discovered in NGINX HTTP/3 Module

blue padlock
Maxim Zhgulev / Unsplash

A vulnerability has been revealed in the HTTP/3 implementation of the web server NGINX. An update is available to address this issue.

On September 15, 2026, F5 published a security advisory disclosing the vulnerability identified as CVE-2026-90439.

The vulnerability involves a heap-based buffer overflow occurring in the module that processes HTTP/3. If HTTP/3 is used with OpenSSL 3.5.0 or earlier versions under certain configurations, a limited heap buffer overflow may occur during the TLS handshake process, potentially leading to denial of service or limited data corruption.

The affected systems include the open-source version of NGINX, the commercial version NGINX Plus, as well as the NGINX Ingress Controller, NGINX Gateway Fabric, and NGINX Instance Manager.