Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5355 articles · 221122 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-90439PATCHED
F5 · NGINX Plus

NGINX ngx_http_v3_module vulnerability

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
F5NGINX Plus37.1.0.1, 37.0.0.1, 1.29.2, 1.30.4

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
f5nginx open sourcemitre_affected90%
nginxnginxcert_advisory90%

References

  • https://my.f5.com/manage/s/article/K000162604(vendor-advisory)

Related News (4 articles)

Tier B
BSI Advisories6d ago
[NEU] [mittel] NGINX: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier E
Hacker News6d ago
Nginx 1.30.5 and 1.31.6 fix HTTP/3 buffer overflow (CVE-2026-90439)
→ No new info (linked only)
Tier B
CERT-FR6d ago
Vulnérabilité dans F5 NGINX (16 septembre 2026)
→ No new info (linked only)
Tier C
VulDB7d ago
CVE-2026-90439 | F5 NGINX Plus/NGINX Open Source ngx_http_v3_module heap-based overflow
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
37.1.1.137.0.6.11.31.61.30.5
CWECWE-122
PublishedSep 15, 2026
Last enriched7d ago
Trending Score25
Source articles4
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-94127EXPKEV
BIG-IP APM OAuth vulnerability
Trending: 140
HIGHCVE-2026-78222
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-66842
BIG-IP and BIG-IQ Configuration utility vulnerability
Trending: 6
HIGHCVE-2026-18329
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-78689
NGINX ngx_http_js_module vulnerablility
Trending: 5

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026
Patch Available
Sep 16, 2026