Risks
- Data integrity compromise
- Remote denial of service
Affected Systems
- NGINX Gateway Fabric versions prior to 2.7.2
- NGINX Ingress Controller versions prior to 5.6.3
- NGINX Open Source versions 1.31.x prior to 1.31.6
- NGINX Open Source versions prior to 1.30.5
- NGINX Plus versions 37.1.x prior to 37.1.1.2
- NGINX Plus versions 37.x prior to 37.0.6.2
Summary
A vulnerability has been discovered in F5 NGINX. It allows an attacker to cause a remote denial of service and data integrity compromise.
Solutions
Refer to the vendor's security bulletin for patches (see Documentation section).
Documentation
- F5 Security Bulletin K000162604 of September 15, 2026 https://my.f5.com/manage/s/article/K000162604
- CVE Reference CVE-2026-90439 https://www.cve.org/CVERecord?id=CVE-2026-90439
