Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78689— NGINX ngx_http_js_module vulnerablility

Quick assessment

Affected
F5 NGINX JavaScript
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 描述 NGINX JavaScript(njs)在 XML 模块的命名空间前缀列表解析器中存在一个漏洞,该漏洞可通过 方法触发。当受影响的 NGINX 配置将外部可控的 XML 命名空间前缀列表传递给该方法时,未认证的远程攻击者可触发此漏洞。njs 和 QuickJS(qjs)两种引擎均受此漏洞影响。 一个精心构造的前缀列表会导致堆分配末尾之外的越界写入。在使用 njs 引擎(即未配置 指令时默认使用的引擎)的情况下,这种越界写入会破坏相邻对象并导致 NGINX 工作进程崩溃。在使

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78689

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NGINX ngx_http_js_module vulnerablility
Source: CVE Program / CVE List V5
Vulnerability Description
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control.   Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
F5 NGINX JavaScript 0.7.10 ~ 1.0.1 -

II. Public POCs for CVE-2026-78689

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78689

登录查看更多情报信息。

Other References for CVE-2026-78689 (1)

Same Patch Batch · F5 · 2026-09-02 · 7 CVEs total

CVE-2026-66842 8.8 HIGH BIG-IP and BIG-IQ Configuration utility vulnerability
CVE-2026-77180 8.3 HIGH NGINX Ingress Controller vulnerability
CVE-2026-18329 8.2 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-66362 8.1 HIGH NGF vulnerability
CVE-2026-78222 7.5 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-63020 3.1 LOW BIG-IP Configuration utility vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-78689

No comments yet


Leave a comment