CVE-2026-18329
published 2026-09-02CVE-2026-18329: Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an…
PriorityP355high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.38%
31.0th percentile
Description
NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources.
Impact
This vulnerability may allow remote attackers to bypass js_access controls. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_javascript | >= 0.9.9 < * | * |
| f5 | nginx_javascript | >= 1.0.0 < 1.0.1 | 1.0.1 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
F5 NGINX JavaScript up to 1.0.0 js_access authorization (CNNVD-2026-99167667)
vuldb·2026-09-04·CVSS 8.2
CVE-2026-18329 [HIGH] F5 NGINX JavaScript up to 1.0.0 js_access authorization (CNNVD-2026-99167667)
A vulnerability, which was classified as critical, was found in F5 NGINX JavaScript up to 1.0.0. Affected by this issue is some unknown functionality of the component js_access. The manipulation results in authorization bypass.
This vulnerability is known as CVE-2026-18329. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
GHSA
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous
ghsa_unreviewed·2026-09-02
CVE-2026-18329 [HIGH] CWE-636 Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous
Description
NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources.
Impact
This vulnerability may allow remote attackers to bypass js_access controls. There is no control plane exposure; this is a data plane issue only.
Note
F5
CVE-2026-18329: Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs ...
vendor_f5·2026-09-02·CVSS 8.2
CVE-2026-18329 [HIGH] CWE-636 CVE-2026-18329: Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs ...
CVE-2026-18329: Description
NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs ...
Description
NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources.
Impact
This vulnerab
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-02
Published