cbcvebase.

F5 Nginx Javascript vulnerabilities

4 known vulnerabilities affecting f5/nginx_javascript.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3

Vulnerabilities

Page 1 of 1
CVE-2026-8711P2CRITICALCVSS 9.8≥ 0.9.4, < 0.9.92026-05-19
CVE-2026-8711 [CRITICAL] CWE-122 CVE-2026-8711: NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least o NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This ma
nvd
CVE-2026-18329P3HIGHCVSS 8.2≥ 1.0.0, < 1.0.1≥ 0.9.9, < *2026-09-02
CVE-2026-18329 [HIGH] CWE-636 CVE-2026-18329: Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HT
nvd
CVE-2026-78689P3HIGHCVSS 8.1≥ 0.7.10, < 1.0.12026-09-02
CVE-2026-78689 [HIGH] CWE-122 CVE-2026-78689: Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list p Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) en
nvd
CVE-2026-78222P3HIGHCVSS 7.5≥ 0.5.1, < 1.0.12026-09-02
CVE-2026-78222 [HIGH] CWE-476 CVE-2026-78222: A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() c A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX
nvd
F5 Nginx Javascript vulnerabilities | cvebase