---
title: Vulnerability Discovered in NGINX HTTP/3 Module
url: https://www.dataloco.com/en/vulnerability-discovered-in-nginx-http3-module
published: 2026-09-26T19:22:10+00:00
language: en
section: Security
source: https://www.security-next.com/190619
organizations: nginx
publisher: Dataloco
---

# Vulnerability Discovered in NGINX HTTP/3 Module

A vulnerability has been revealed in the HTTP/3 implementation of the web server NGINX. An update is available to address this issue.

On September 15, 2026, F5 published a security advisory disclosing the vulnerability identified as CVE-2026-90439.

The vulnerability involves a heap-based buffer overflow occurring in the module that processes HTTP/3. If HTTP/3 is used with OpenSSL 3.5.0 or earlier versions under certain configurations, a limited heap buffer overflow may occur during the TLS handshake process, potentially leading to denial of service or limited data corruption.

The affected systems include the open-source version of NGINX, the commercial version NGINX Plus, as well as the NGINX Ingress Controller, NGINX Gateway Fabric, and NGINX Instance Manager.
