On September 15, 2026 nginx released stable 1.30.5 and mainline 1.31.6 to fix one security issue, CVE-2026-90439. In the words of the official change log, under certain configurations a heap memory buffer overflow might occur in a worker process when using HTTP/3 with OpenSSL 3.5.0 and earlier. The advisory files it under ngx_http_v3_module, rates it medium, lists 1.29.2 through 1.31.5 as vulnerable, and 1.30.5 and 1.31.6 onwards as fixed.

First, Work Out Whether You're Exposed

You are affected only if all three hold:

  • Your version is between 1.29.2 and 1.31.5: nginx -v.
  • HTTP/3 is enabled: a listen ... quic line. Check the full effective configuration with nginx -T | grep -n quic, not just the main file.
  • It was built against OpenSSL 3.5.0 or earlier: nginx -V prints "built with OpenSSL x.y.z".

Sites without HTTP/3 are not exposed to this bug. The release also carries one behaviour change: a QUIC transport parameters extension received on an ordinary TLS connection is now always ignored. Normal clients never send that, so you shouldn't notice.

Don't Forget njs and the July Batch

If you use njs, nginx's JavaScript module, njs 1.0.1 (September 2) fixed three vulnerabilities: an access control bypass in js_access (CVE-2026-18329), a worker crash in ngx.fetch() (CVE-2026-78222) and a heap buffer overflow in xml.exclusiveC14n() (CVE-2026-78689).

And if you are still below 1.30.4, there is more to fix than this. The July 15 release 1.30.4 fixed the map-plus-regex buffer overflow (CVE-2026-42533, covered in detail in our article at the time), uninitialised memory access in the slice module (CVE-2026-60005) and a use-after-free in the SSI module (CVE-2026-56434). Going straight to 1.30.5 settles all of it.

When You Upgrade

  • Distribution packages usually backport fixes, so the version won't read 1.30.5 — rely on your distro's security advisory. If you use the official nginx repository, move to 1.30.5 or 1.31.6.
  • Run nginx -t before reloading to confirm the configuration passes. HTTP/3 runs over UDP 443, so verify it from outside after the upgrade.
  • If you are still building your first site, building your first website with Nginx and configuring a Let's Encrypt SSL certificate cover the basics, and if a site stops loading after an upgrade or reload, work through the 502 / 504 troubleshooting guide.