Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Nginx Plus von F5
NGINX Plus PLS.37.0.6.2 LTS: Fix für HTTP/3-Sicherheitslücke
NGINX Plus PLS.37.0.6.2 LTS (basierend auf NGINX Open Source 1.29.8) behebt eine Sicherheitslücke im Modul ngx_http_v3_module, bei der mit HTTP/3 und OpenSSL 3.5.0 oder früher beim TLS-Handshake ein begrenzter Heap-Buffer-Overflow auftreten kann (CVE-2026-90439).
September 15, 2026
Based on NGINX Open Source 1.29.8
NGINX Plus PLS.37.0.6.2 LTS is a security release.
- Security fix in the
ngx_http_v3_modulemodule: when using HTTP/3 with OpenSSL versions 3.5.0 and earlier, a limited heap buffer overflow may occur during TLS handshake processing under certain configurations. The condition is non-deterministic and beyond an attacker’s control. This may cause a heap buffer overflow in the NGINX worker process, potentially resulting in restart and/or limited data corruption. (CVE-2026-90439).
Before upgrading from NGINX Plus R36, review the Upgrade Notes for breaking changes.