VYPR

Njs

by Nginx

Source repositories

CVEs (47)

  • CVE-2020-19695CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.

  • CVE-2020-19692CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.

  • CVE-2019-13067CriJun 30, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.

  • CVE-2019-12208CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c.

  • CVE-2019-12207CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.

  • CVE-2019-12206CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c.

  • CVE-2019-11839CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.

  • CVE-2019-11838CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling.

  • CVE-2022-34029CriJul 18, 2022
    risk 0.59cvss 9.1epss 0.01

    Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h.

  • CVE-2026-78689HigSep 2, 2026
    risk 0.53cvss 8.1epss 0.01

    Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML…

  • CVE-2026-18329HigSep 2, 2026
    risk 0.53cvss 8.2epss 0.00

    Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An…

  • CVE-2026-8711HigMay 19, 2026
    risk 0.53cvss 8.1epss 0.01

    NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker…

  • CVE-2020-24346HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.01

    njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.

  • CVE-2023-27730HigApr 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c.

  • CVE-2023-27729HigApr 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c.

  • CVE-2023-27728HigApr 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c.

  • CVE-2023-27727HigApr 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.

  • CVE-2022-43285HigOct 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.

  • CVE-2022-43284HigOct 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.

  • CVE-2022-34032HigJul 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Nginx NJS v0.7.5 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.

Page 1 of 3