Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78222— NGINX ngx_http_js_module vulnerability

Quick assessment

Affected
F5 NGINX JavaScript
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

NGINX JavaScript 中存在一个漏洞:当可信的 JavaScript 代码读取 时, 接收到格式异常的 HTTP 响应可能会导致 NGINX 工作进程(worker)崩溃。利用该漏洞需要对所获取的 HTTP 响应具有控制权或施加影响。 影响: 该漏洞可能允许远程攻击者对 NGINX 系统造成拒绝服务(DoS)。控制平面不受影响;这仅是一个数据平面的问题。 注意: 已到达技术支持终止(End of Technical Support, EoTS)的软件版本未纳入评估范围。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78222

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NGINX ngx_http_js_module vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
F5 NGINX JavaScript 0.5.1 ~ 1.0.1 -

II. Public POCs for CVE-2026-78222

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78222

登录查看更多情报信息。

Other References for CVE-2026-78222 (1)

Same Patch Batch · F5 · 2026-09-02 · 7 CVEs total

CVE-2026-66842 8.8 HIGH BIG-IP and BIG-IQ Configuration utility vulnerability
CVE-2026-77180 8.3 HIGH NGINX Ingress Controller vulnerability
CVE-2026-18329 8.2 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-78689 8.1 HIGH NGINX ngx_http_js_module vulnerablility
CVE-2026-66362 8.1 HIGH NGF vulnerability
CVE-2026-63020 3.1 LOW BIG-IP Configuration utility vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-78222

No comments yet


Leave a comment