Количество 8
Количество 8
BDU:2026-09782
Уязвимость модуля ngx_http_js_module JavaScript-интерпретатора NGINX JavaScript (njs), позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
ROS-20260629-73-0021
Уязвимость angie
ROS-20260626-73-0001
Уязвимость nginx
CVE-2026-8711
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-8711
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-8711
NGINX JavaScript vulnerability
CVE-2026-8711
NGINX JavaScript has a vulnerability when the js_fetch_proxydirective ...
GHSA-pj32-6rxc-gcmq
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-09782 Уязвимость модуля ngx_http_js_module JavaScript-интерпретатора NGINX JavaScript (njs), позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
ROS-20260629-73-0021 Уязвимость angie | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
ROS-20260626-73-0001 Уязвимость nginx | CVSS3: 8.1 | 1% Низкий | около 1 месяца назад | |
CVE-2026-8711 NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8711 NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8711 NGINX JavaScript vulnerability | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-8711 NGINX JavaScript has a vulnerability when the js_fetch_proxydirective ... | CVSS3: 8.1 | 1% Низкий | 2 месяца назад | |
GHSA-pj32-6rxc-gcmq NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 8.1 | 1% Низкий | 2 месяца назад |
Уязвимостей на страницу