Critical severity9.8NVD Advisory· Published May 9, 2019· Updated Jun 17, 2026
CVE-2019-11838
CVE-2019-11838
Description
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- NGINX/njsdescription
Patches
Vulnerability mechanics
References
1- github.com/nginx/njs/issues/153nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.