Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5355 articles · 221122 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-78689PATCHED
f5 · nginx

NGINX ngx_http_js_module vulnerablility

Description

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control.   Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx0.7.10

References

  • https://my.f5.com/manage/s/article/K000162602(vendor-advisory)

Related News (2 articles)

Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits F5 (03 septembre 2026)
→ No new info (linked only)
Tier C
VulDB20d ago
CVE-2026-78689 | F5 NGINX JavaScript up to 1.0.0 XML module xml.exclusiveC14n out-of-bounds write
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.0.1
CWECWE-122
PublishedSep 2, 2026
Trending Score5
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-94127EXPKEV
BIG-IP APM OAuth vulnerability
Trending: 140
MEDIUMCVE-2026-90439
NGINX ngx_http_v3_module vulnerability
Trending: 25
HIGHCVE-2026-78222
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-66842
BIG-IP and BIG-IQ Configuration utility vulnerability
Trending: 6
HIGHCVE-2026-18329
NGINX ngx_http_js_module vulnerability
Trending: 6

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 2, 2026
Discovered by ZDM
Sep 2, 2026
Patch Available
Sep 3, 2026