- Sources: primary, downloads, discussion
- Summary: The nginx security advisories page lists CVE-2026-90439, a buffer overflow in ngx_http_v3_module that the project rates medium. Versions 1.29.2 through 1.31.5 are listed as vulnerable, and 1.31.6 mainline and 1.30.5 stable as not vulnerable. The advisory is silent on exploitation and carries no proof of concept.
- Why it matters: Exposure is limited to builds that include and serve HTTP/3, which is not the default, so the practical check is whether a deployment compiled and enabled that module.
send feedback on this story