CVE-2026-90439

Public on 2026-09-15
Modified on 2026-09-17
Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption.

Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only.




Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Nginx1 Extra nginx Pending Fix
Amazon Linux 2 - Nginx1.12 Extra nginx No Fix Planned
Amazon Linux 2023 nginx Not Affected
Amazon Linux 2027 Preview nginx Not Affected
Amazon Linux 2027 Preview nginx-awslc Not Affected
Amazon Linux 2023 nginx-mod-headers-more Not Affected
Amazon Linux 2027 Preview nginx-mod-headers-more Not Affected
Amazon Linux 2023 nginx-mod-njs Not Affected
Amazon Linux 2027 Preview nginx-mod-njs Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L