nginx 1.31.6 Patches Heap Buffer Overflow in HTTP/3 (CVE-2026-90439)

jedisct1 · x · 2026-09-16

nginx 1.31.6 is out with a security fix for CVE-2026-90439: a heap memory buffer overflow can occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier.

Original post →

More from Infra

Infra channel →