Denial-of-Service Vulnerability in NGINX JavaScript Plugin by NGINX
CVE-2026-78222
8.7HIGH
What is CVE-2026-78222?
A vulnerability in the NGINX JavaScript module allows for a denial-of-service condition due to a malformed HTTP response processed by the ngx.fetch() function. When trusted JavaScript attempts to read the Response.statusText from an improperly formatted HTTP response, it can lead to the crashing of an NGINX worker process. To exploit this vulnerability, an attacker must control or influence the response received, thereby impacting the availability of the affected NGINX system.
Affected Version(s)
NGINX JavaScript 0.5.1 < 1.0.1
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
F5 acknowledges Sujal Tuladhar (EvilGenius) and YuuLuo for bringing this issue to our attention and following the highest standards of coordinated disclosure.