Heap Buffer Overflow in NGINX Open Source and NGINX Plus due to HTTP/3 Configuration
CVE-2026-90439
6.9MEDIUM
What is CVE-2026-90439?
The ngx_http_v3_module in both NGINX Plus and NGINX Open Source is susceptible to a limited heap buffer overflow during TLS handshake processes when utilizing HTTP/3 in conjunction with OpenSSL versions less than or equal to 3.5.0 under specific configurations. This vulnerability presents varying attack patterns, potentially allowing remote attackers to induce a denial-of-service (DoS) event, leading to service disruptions and/or limited data corruption as the NGINX worker process may restart unexpectedly. Notably, this vulnerability does not expose the control plane, affecting only the data plane.
Affected Version(s)
NGINX Open Source 1.29.2 < 1.31.6
NGINX Open Source 1.30.4 < 1.30.5
NGINX Plus 37.1.0.1 < 37.1.1.1
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
F5 acknowledges Banny Liao for bringing this issue to our attention and following the highest standards of coordinated disclosure.