FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

nginx -- buffer overflow when using ngx_http_v3_module

Affected packages
nginx < 1.30.5,3
nginx-devel < 1.31.6

Details

VuXML ID 7dc8fd4b-b1a7-11f1-a655-3497f65b111b
Discovery 2026-09-15
Entry 2026-09-16

The nginx development team reports:

Buffer overflow when using ngx_http_v3_module (CVE-2026-90439). Severity: medium.

A heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier.

References

CVE Name CVE-2026-90439
URL https://my.f5.com/manage/s/article/K000162604
URL https://nginx.org/en/security_advisories.html