---
id: CVE-2026-90439
title: >-
  NGINX Plus and NGINX Open Source have a vulnerability in the
  ngx_http_v3_module module
summary: >-
  NGINX Plus and NGINX Open Source have a vulnerability in the
  ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL
  3.5.0 under certain configurations, a limited heap buffer overflow could
  happen while processing a…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-122
  - CWE-787
vendor: F5
product: NGINX Plus
affected:
  - nginx_plus >= 37.1.0.1 < 37.1.1.1
  - nginx_plus >= 37.0.0.1 < 37.0.6.1
  - nginx_open_source >= 1.29.2 < 1.31.6
  - nginx_open_source >= 1.30.4 < 1.30.5
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:34:36.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90439'
references:
  - url: 'https://my.f5.com/manage/s/article/K000162604'
    label: f5sirt@f5.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90439.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90439'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533856'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90439'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90439'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67977'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00425
epssPercentile: 0.34126
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T14:48:56.965070Z'
ingestedAt: '2026-09-15T14:38:16.198Z'
patched:
  - hardened_images
---

## Overview

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption.

Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only.




Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:67977** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67977)
- **Red Hat VEX** · Moderate · affected: Red Hat Hardened Images, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4, Red Hat Hardened Images · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90439.json)
