Search CVE reports


Toggle filters

1 – 3 of 3 results


CVE-2026-78689

Medium priority
Needs evaluation

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected...

1 affected package

libnginx-mod-js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnginx-mod-js Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-78222

Medium priority
Needs evaluation

A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the...

1 affected package

libnginx-mod-js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnginx-mod-js Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-8711

Medium priority
Fixed

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation...

1 affected package

libnginx-mod-js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libnginx-mod-js Fixed Not affected Not in release
Show less packages