Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18329— NGINX ngx_http_js_module vulnerability

Quick assessment

Affected
F5 NGINX JavaScript
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述 NGINX JavaScript(njs)和 QuickJS(qjs)引擎存在一个漏洞:当 处理器执行异步请求体处理,且在返回显式访问拒绝之前,异步访问控制评估过程中抛出异常时,该漏洞即被触发。未认证的攻击者可以通过发送一个精心构造的 HTTP 请求,从而触发访问验证逻辑中的错误状态。这可能导致 阶段“失败开放”(fail-open),使得本应被拒绝的请求得以继续执行,进而导致认证或授权被绕过,造成对受保护资源的未授权访问。 影响 该漏洞可能允许远程攻击者绕过 控制机制。该问题仅存在于数据平面,不涉及控制

CVSS 8.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18329

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NGINX ngx_http_js_module vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources. Impact This vulnerability may allow remote attackers to bypass js_access controls. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
未能安全地进行程序失效(Failing Open)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
F5 NGINX JavaScript 1.0.0 ~ 1.0.1 -

II. Public POCs for CVE-2026-18329

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18329

登录查看更多情报信息。

Other References for CVE-2026-18329 (1)

Same Patch Batch · F5 · 2026-09-02 · 7 CVEs total

CVE-2026-66842 8.8 HIGH BIG-IP and BIG-IQ Configuration utility vulnerability
CVE-2026-77180 8.3 HIGH NGINX Ingress Controller vulnerability
CVE-2026-78689 8.1 HIGH NGINX ngx_http_js_module vulnerablility
CVE-2026-66362 8.1 HIGH NGF vulnerability
CVE-2026-78222 7.5 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-63020 3.1 LOW BIG-IP Configuration utility vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-18329

No comments yet


Leave a comment