# F5 NGINX Open Source patches DoS flaw

Published: 2026-09-16 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/54f85bf7-8617-5e42-b1d7-bfffb3f9108c/f5-nginx-open-source-patches-dos-flaw

> CERT-FR advisory details a NGINX Open Source vulnerability allowing remote denial of service and data integrity compromise, fixed in versions 1.31.6 and 1.30.5.

CERT-FR published an advisory on September 2026 covering a vulnerability in F5's NGINX Open Source software, tracked as CVE-2026-90439. The flaw affects NGINX Open Source versions 1.31.x prior to 1.31.6, as well as versions up to 1.30.5, and allows a remote attacker to trigger a denial-of-service condition and compromise the integrity of data. The advisory does not indicate that the vulnerability is currently being exploited in the wild.

Defenders running affected NGINX Open Source deployments should consult F5's security bulletin (K000162604, published 15 September 2026) and apply the vendor's patches promptly. No proof-of-concept or exploitation details are included in this advisory; organizations should prioritize patching based on their exposure of internet-facing NGINX instances and internal risk assessment.

## Mentioned in this report

- Vulnerabilities: CVE-2026-90439

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1182

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/54f85bf7-8617-5e42-b1d7-bfffb3f9108c/f5-nginx-open-source-patches-dos-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
