VYPR

NGINX JavaScript

by Nginx

CVEs (2)

  • CVE-2026-8711HigMay 19, 2026
    risk 0.53cvss 8.1epss 0.10

    NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker…

  • CVE-2026-78222HigSep 2, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability…