CVE-2026-90439

NameCVE-2026-90439
DescriptionNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nginx (PTS)bookworm1.22.1-9+deb12u9fixed
bookworm (security)1.22.1-9+deb12u10fixed
trixie1.26.3-3+deb13u7fixed
trixie (security)1.26.3-3+deb13u9fixed
forky, sid1.30.4-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nginxsourcebookworm(not affected)
nginxsourcetrixie(not affected)
nginxsource(unstable)1.30.4-7

Notes

[trixie] - nginx <not-affected> (Vulnerable code not present)
[bookworm] - nginx <not-affected> (Vulnerable code not present)
https://my.f5.com/manage/s/article/K000162604
Introduced with: https://github.com/nginx/nginx/commit/0373fe5d98c1515640e74fa6f4d32fac1f1d3ab2 (release-1.29.2)
Fixed by: https://github.com/nginx/nginx/commit/7c7363266d54bc3836c1d13d1ed1e1d93ee9ed98 (release-1.31.6)
Fixed by: https://github.com/nginx/nginx/commit/78399582a5d6d212e40ffc7f9ca61e6de7852d9c (release-1.30.5)

Search for package or bug name: Reporting problems