Nginx 1.31.6 Released with Fix for HTTP/3 Buffer Overflow

The release of the main branch of nginx 1.31.6 has been published, in which the development of new features continues. In parallel, the stable branch 1.30.x is supported, only changes related to the elimination of serious errors and vulnerabilities are made. In the future, the stable branch 1.31 will be formed on the basis of the main branch 1.32.x. The project code is written in C and is distributed under the BSD license.

This release fixes a vulnerability (CVE-2026-90439) in the ngx_http_v3_module module that causes a buffer overflow when manipulating parameters during the TLS handshake phase. It is stated that an attacker cannot control data written to the out-of-buffer area, and the vulnerability is limited to denial of service or data corruption. The issue manifests itself starting with nginx 1.29.2 in configurations built with OpenSSL 3.5.0 and earlier.

Other changes include bug fixes and a move to ignoring all QUIC transport protocol parameters received during the TLS connection establishment process.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster