Heap-based buffer overflow in NGINX Open Source and NGINX Plus - CVE-2026-90439
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or limited data corruption.
The vulnerability exists due to a heap-based buffer overflow in the ngx_http_v3_module module when processing a TLS handshake over HTTP/3. A remote attacker can initiate a TLS handshake to cause a denial of service or limited data corruption.
The issue occurs non-deterministically and is beyond the attacker\'s control. Only configurations using HTTP/3 with OpenSSL 3.5.0 or earlier are affected.
Affected software
NGINX Plus
How to mitigate CVE-2026-90439
NGINX Plus - addressed in versions 37.0.6.1, 37.1.1.1