以下是该漏洞描述信息的中文翻译: 描述 NGINX JavaScript(njs)在 XML 模块的命名空间前缀列表解析器中存在一个漏洞,该漏洞可通过 方法触发。当受影响的 NGINX 配置将外部可控的 XML 命名空间前缀列表传递给该方法时,未认证的远程攻击者可触发此漏洞。njs 和 QuickJS(qjs)两种引擎均受此漏洞影响。 一个精心构造的前缀列表会导致堆分配末尾之外的越界写入。在使用 njs 引擎(即未配置 指令时默认使用的引擎)的情况下,这种越界写入会破坏相邻对象并导致 NGINX 工作进程崩溃。在使
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX JavaScript | 0.7.10 ~ 1.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66842 | 8.8 HIGH | BIG-IP and BIG-IQ Configuration utility vulnerability |
| CVE-2026-77180 | 8.3 HIGH | NGINX Ingress Controller vulnerability |
| CVE-2026-18329 | 8.2 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-66362 | 8.1 HIGH | NGF vulnerability |
| CVE-2026-78222 | 7.5 HIGH | NGINX ngx_http_js_module vulnerability |
| CVE-2026-63020 | 3.1 LOW | BIG-IP Configuration utility vulnerability |
No comments yet