Skip to content
Threat Feed
medium advisory

Vulnerability in F5 NGINX

A vulnerability in F5 NGINX, tracked as CVE-2026-90439, allows remote attackers to trigger a denial of service and potentially compromise data integrity.

CVE search metadata

CVE search record: CVE-2026-90439. Severity: medium. CVSS: 6.5. KEV: no. Product: NGINX Open Source (< 1.31.6), NGINX Open Source (<= 1.30.5). Brief: Vulnerability in F5 NGINX. Brief link: https://feed.craftedsignal.io/briefs/2026-09-nginx-vulnerability/

F5 has published a security bulletin regarding a vulnerability identified in NGINX Open Source, documented as CVE-2026-90439. This vulnerability exposes affected systems to remote denial-of-service (DoS) conditions and potential data integrity compromises. The issue impacts NGINX Open Source versions in the 1.31.x branch prior to 1.31.6, as well as versions up to and including 1.30.5. As NGINX is frequently deployed as a reverse proxy, load balancer, or web server at the perimeter of enterprise environments, the ability for remote, unauthenticated attackers to cause service disruptions or data inconsistencies poses a significant operational and security risk. Defenders should assess their NGINX deployment versions and apply the patches provided by F5 in their security bulletin K000162604 to mitigate the risk of exploitation.

Impact

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to disrupt availability via a denial-of-service attack. Additionally, the vulnerability can lead to data integrity issues within the affected NGINX instance, potentially impacting the reliability of traffic passing through the proxy or the server itself. This could result in service outages and the corruption of data handled by the NGINX software.

Recommendation

  • Audit all internet-facing and internal NGINX Open Source installations to identify versions 1.31.x (prior to 1.31.6) and versions <= 1.30.5.
  • Patch affected instances immediately by upgrading to the secure versions recommended in F5 security bulletin K000162604.
  • Review NGINX configuration and access logs for anomalous traffic patterns or unexpected service restarts that may indicate attempted exploitation of CVE-2026-90439.

Threat Hunt

Monitor NGINX error logs for signs of process crashes or unexpected service termination.

medium medium confidence hunt now

Data: NGINX error logs

Mitigations

Upgrade NGINX Open Source to 1.31.6 or later

immediate IT Operations

CVE-2026-90439