logo

Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows

ID: 03579fd3-7ede-598f-bd91-5dd00181bab0

STIX ID: report--03579fd3-7ede-598f-bd91-5dd00181bab0

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

F5 warns of a critical heap-buffer-overflow in the NGINX JavaScript (njs) module (CVE-2026-8711, CVSS 9.2) that can be triggered when js_fetch_proxy expands client-controlled variables into URLs used by ngx.fetch; an unauthenticated attacker can cause worker crashes (DoS) and, on systems without ASLR, potentially achieve remote code execution. Affected njs versions are 0.9.4–0.9.8 and the issue is fixed in 0.9.9.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.