Release of nginx 1.31.6 addressing buffer overflow in the HTTP/3 implementation

The release of the main branch nginx 1.31.6 has been published, continuing the development of new features. The parallel stable branch 1.30.x will only receive changes related to fixing critical bugs and vulnerabilities. In the future, a stable branch 1.32 will be formed based on the main branch 1.31.x. The project code is written in C and distributed under the BSD license.

In the new release, a vulnerability (CVE-2026-90439) in the ngx_http_v3_module has been fixed, which can lead to a buffer overflow when manipulating parameters during the TLS connection negotiation phase. It is claimed that an attacker cannot control the data written to the buffer overflow area, and the vulnerability is limited to denial of service or data corruption. The issue manifests starting from the release of nginx 1.29.2 in configurations built with OpenSSL 3.5.0 and earlier.

Other changes include bug fixes and a transition to ignoring all QUIC transport protocol parameters received during the TLS connection setup.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster