Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5329 articles · 221079 vulns · 37/41 feeds (7d)
← Back to list
8.2
CVE-2026-18329PATCHED
f5 · nginx

NGINX ngx_http_js_module vulnerability

Description

Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources. Impact This vulnerability may allow remote attackers to bypass js_access controls. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx1.0.0, 0.9.9

References

  • https://my.f5.com/manage/s/article/K000162599(vendor-advisory)

Related News (2 articles)

Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits F5 (03 septembre 2026)
→ No new info (linked only)
Tier C
VulDB20d ago
CVE-2026-18329 | F5 NGINX JavaScript up to 1.0.0 js_access authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.0.1*
CWECWE-636
PublishedSep 2, 2026
Trending Score6
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-94127EXPKEV
BIG-IP APM OAuth vulnerability
Trending: 141
MEDIUMCVE-2026-90439
NGINX ngx_http_v3_module vulnerability
Trending: 26
HIGHCVE-2026-78222
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-66842
BIG-IP and BIG-IQ Configuration utility vulnerability
Trending: 6
HIGHCVE-2026-78689
NGINX ngx_http_js_module vulnerablility
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 2, 2026
Discovered by ZDM
Sep 2, 2026
Patch Available
Sep 2, 2026