F5 NGINX Open Source patches DoS flaw
CERT-FR advisory details a NGINX Open Source vulnerability allowing remote denial of service and data integrity compromise, fixed in versions 1.31.6 and 1.30.5.
CERT-FR published an advisory on September 2026 covering a vulnerability in F5's NGINX Open Source software, tracked as CVE-2026-90439. The flaw affects NGINX Open Source versions 1.31.x prior to 1.31.6, as well as versions up to 1.30.5, and allows a remote attacker to trigger a denial-of-service condition and compromise the integrity of data. The advisory does not indicate that the vulnerability is currently being exploited in the wild.
Defenders running affected NGINX Open Source deployments should consult F5's security bulletin (K000162604, published 15 September 2026) and apply the vendor's patches promptly. No proof-of-concept or exploitation details are included in this advisory; organizations should prioritize patching based on their exposure of internet-facing NGINX instances and internal risk assessment.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1182
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free