CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-90439

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-09-15
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

⚡ Watch CVE-2026-90439

Get an email if CVE-2026-90439 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-90439

CVE.org record

Embed the live status

CVE-2026-90439 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-90439 status](https://www.csirts.com/badge/CVE-2026-90439)](https://www.csirts.com/cve/CVE-2026-90439)