NGINX JavaScript 中存在一个漏洞:当可信的 JavaScript 代码读取 时, 接收到格式异常的 HTTP 响应可能会导致 NGINX 工作进程(worker)崩溃。利用该漏洞需要对所获取的 HTTP 响应具有控制权或施加影响。 影响: 该漏洞可能允许远程攻击者对 NGINX 系统造成拒绝服务(DoS)。控制平面不受影响;这仅是一个数据平面的问题。 注意: 已到达技术支持终止(End of Technical Support, EoTS)的软件版本未纳入评估范围。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX JavaScript | 0.5.1 ~ 1.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66842 | 8.8 HIGH | BIG-IP and BIG-IQ Configuration utility vulnerability |
| CVE-2026-77180 | 8.3 HIGH | NGINX Ingress Controller vulnerability |
| CVE-2026-18329 | 8.2 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-78689 | 8.1 HIGH | NGINX ngx_http_js_module vulnerablility |
| CVE-2026-66362 | 8.1 HIGH | NGF vulnerability |
| CVE-2026-63020 | 3.1 LOW | BIG-IP Configuration utility vulnerability |
No comments yet