CVE-2026-78689
- EPSS 0.41%
- Veröffentlicht 02.09.2026 15:40:55
- Zuletzt bearbeitet 03.09.2026 13:06:10
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes...
CVE-2026-18329
- EPSS 0.38%
- Veröffentlicht 02.09.2026 15:40:54
- Zuletzt bearbeitet 03.09.2026 16:37:52
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit acce...
CVE-2026-8711
- EPSS 0.89%
- Veröffentlicht 19.05.2026 14:04:18
- Zuletzt bearbeitet 23.07.2026 20:10:00
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript....
CVE-2023-27730
- EPSS 0.74%
- Veröffentlicht 09.04.2023 20:15:56
- Zuletzt bearbeitet 11.02.2025 22:15:26
Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c.
CVE-2023-27729
- EPSS 0.66%
- Veröffentlicht 09.04.2023 20:15:56
- Zuletzt bearbeitet 12.02.2025 16:15:37
Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.
CVE-2023-27728
- EPSS 0.74%
- Veröffentlicht 09.04.2023 20:15:56
- Zuletzt bearbeitet 11.02.2025 20:15:32
Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c.
CVE-2023-27727
- EPSS 0.73%
- Veröffentlicht 09.04.2023 20:15:56
- Zuletzt bearbeitet 12.02.2025 16:15:37
Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.
CVE-2020-19695
- EPSS 1.33%
- Veröffentlicht 04.04.2023 15:15:07
- Zuletzt bearbeitet 12.08.2025 18:09:57
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
CVE-2020-19692
- EPSS 1.32%
- Veröffentlicht 04.04.2023 15:15:07
- Zuletzt bearbeitet 12.08.2025 17:56:57
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
CVE-2022-43286
- EPSS 0.92%
- Veröffentlicht 28.10.2022 21:15:10
- Zuletzt bearbeitet 07.05.2025 14:15:37
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.