nginx patches a heap overflow in the HTTP/3 handshake of its edge servers
On September 15, 2026, nginx shipped 1.31.6 and 1.30.5 to close CVE-2026-90439, a heap buffer overflow in its HTTP/3 module that hits builds linked against OpenSSL 3.5.0 or earlier. Upgrade both nginx and OpenSSL, then disable HTTP/3 on edges that do not need it.