Product
high
advisory
Authentication Bypass in NGINX JavaScript and QuickJS Engines
1 TTP 1 CVEAn authentication bypass flaw in NGINX JavaScript (njs) and QuickJS (qjs) engines allows unauthenticated attackers to trigger a fail-open state in access control logic, potentially granting unauthorized access to protected resources.
NGINX JavaScript +1
1t
1c
high
advisory
NGINX JavaScript Heap Buffer Overflow Vulnerability (CVE-2026-8711)
2 rules 3 TTPs 1 CVENGINX JavaScript is vulnerable to a heap buffer overflow (CVE-2026-8711) when the js_fetch_proxy directive is configured with client-controlled variables and ngx.fetch(), allowing unauthenticated attackers to cause worker process restarts or, with ASLR disabled, code execution via crafted HTTP requests.
NGINX JavaScript
cve
heap-buffer-overflow
nginx
2r
3t
1c