Advisories
F5 NGINX Remote DoS & Data Integrity Flaw (CVE-2026-90439) – Patch Now
A critical flaw in F5’s NGINX Open Source has been exposed, letting attackers trigger a remote denial‑of‑service and corrupt data integrity. The vulnerability, identified as CVE‑2026‑90439, affects NGINX 1.31.x prior to 1.31.6 and 1.30.5. Immediate patching is essential. F5 has released a security bulletin detailing the fix; administrators should update or apply the vendor’s mitigation steps without delay.
A new critical vulnerability has been uncovered in F5’s NGINX Open Source, enabling attackers to cause a remote denial‑of‑service (DoS) and compromise data integrity. The flaw, catalogued as CVE‑2026‑90439, is exploitable on a range of older NGINX releases.
Impact
- Remote DoS – the affected server can be rendered unresponsive by a single crafted request.
- Data integrity breach – attackers can manipulate or corrupt data handled by the compromised instance.
Affected Versions
- NGINX Open Source 1.31.x – any release before 1.31.6
- NGINX Open Source 1.30.5
Mitigation
- Apply the latest patch released by F5, referenced in Security Bulletin K000162604.
- If immediate patching is not possible, follow the vendor’s temporary mitigation steps outlined in the bulletin.
- Verify that your deployment is not running a vulnerable version by checking the output of
nginx -vor equivalent.
Administrators are urged to act swiftly. Failing to patch exposes services to both disruption and data tampering, potentially violating compliance requirements and damaging customer trust.
Next Steps
- Review your infrastructure for the presence of the affected NGINX versions.
- Download and deploy the official patch from the F5 support portal.
- Test the updated configuration in a staging environment before rolling out to production.
- Monitor logs for anomalous activity that could indicate exploitation attempts.