FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Angie -- worker process memory corruption when using HTTP/3

Affected packages
angie < 1.12.2

Details

VuXML ID 6cf2ff4b-b38c-11f1-a655-3497f65b111b
Discovery 2026-09-17
Entry 2026-09-18

The Angie Software Team reports:

When using an OpenSSL version without native HTTP/3 support (3.5.0 or earlier), if the default server for the address that accepted a regular HTTPS request also used HTTP/3 (the listen directive with the quic parameter, possibly on a different port), while a server block without HTTP/3 was selected by domain name (SNI), limited worker process memory corruption or a worker process crash could occur (CVE-2026-90439); the fix was ported from nginx 1.31.6.

References

CVE Name CVE-2026-90439
URL https://en.angie.software/angie/docs/oss_changes/#angie-1-12-2
URL https://nvd.nist.gov/vuln/detail/CVE-2026-90439