{"id":"CVE-2026-90439","title":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module","summary":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-122","CWE-787"],"vendor":"F5","product":"NGINX Plus","affected":["nginx_plus >= 37.1.0.1 < 37.1.1.1","nginx_plus >= 37.0.0.1 < 37.0.6.1","nginx_open_source >= 1.29.2 < 1.31.6","nginx_open_source >= 1.30.4 < 1.30.5"],"published":"2026-09-15","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:34:36.657","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90439","references":[{"url":"https://my.f5.com/manage/s/article/K000162604","label":"f5sirt@f5.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90439.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-90439"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533856"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90439"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90439"},{"url":"https://access.redhat.com/errata/RHSA-2026:67977"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00256,"epssPercentile":0.17567,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-15T14:48:56.965070Z"},"ingestedAt":"2026-09-15T14:38:16.198Z","patched":["hardened_images"],"slug":"CVE-2026-90439","body":"## Overview\n\nNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:67977** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67977)\n- **Red Hat VEX** · Moderate · affected: Red Hat Hardened Images, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4, Red Hat Hardened Images · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90439.json)","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}