Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows
ID: 03579fd3-7ede-598f-bd91-5dd00181bab0
STIX ID: report--03579fd3-7ede-598f-bd91-5dd00181bab0
Feed Name: securityonline.info
Threat Score
F5 warns of a critical heap-buffer-overflow in the NGINX JavaScript (njs) module (CVE-2026-8711, CVSS 9.2) that can be triggered when js_fetch_proxy expands client-controlled variables into URLs used by ngx.fetch; an unauthenticated attacker can cause worker crashes (DoS) and, on systems without ASLR, potentially achieve remote code execution. Affected njs versions are 0.9.4–0.9.8 and the issue is fixed in 0.9.9.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
