Out-of-Bounds Write Vulnerability in NGINX Affecting XML Module and njs Engine
CVE-2026-78689
What is CVE-2026-78689?
The NGINX JavaScript (njs) engine contains a vulnerability within the XML module's namespace prefix list parser. This vulnerability can be exploited by unauthenticated remote attackers who send a specially crafted XML namespace prefix list to the xml.exclusiveC14n() method via an affected NGINX configuration. The resulting out-of-bounds write can corrupt adjacent memory and lead to NGINX worker crashes, thus causing a denial of service. In particular, the official nginxinc/nginx-saml reference implementation is susceptible, as it mishandles InclusiveNamespaces/@PrefixList from untrusted SAML messages without prior verification of the SAML signature, allowing the exploitation through various SAML requests. Although direct code execution has not yet been confirmed, the potential for such an exploit cannot be dismissed based on current evidence.
Affected Version(s)
NGINX JavaScript 0.7.10 < 1.0.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved