Out-of-Bounds Write Vulnerability in NGINX Affecting XML Module and njs Engine
CVE-2026-78689

9.2CRITICAL

Key Information:

Vendor

F5

Vendor
CVE Published:
2 September 2026

What is CVE-2026-78689?

The NGINX JavaScript (njs) engine contains a vulnerability within the XML module's namespace prefix list parser. This vulnerability can be exploited by unauthenticated remote attackers who send a specially crafted XML namespace prefix list to the xml.exclusiveC14n() method via an affected NGINX configuration. The resulting out-of-bounds write can corrupt adjacent memory and lead to NGINX worker crashes, thus causing a denial of service. In particular, the official nginxinc/nginx-saml reference implementation is susceptible, as it mishandles InclusiveNamespaces/@PrefixList from untrusted SAML messages without prior verification of the SAML signature, allowing the exploitation through various SAML requests. Although direct code execution has not yet been confirmed, the potential for such an exploit cannot be dismissed based on current evidence.

Affected Version(s)

NGINX JavaScript 0.7.10 < 1.0.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5 acknowledges Vladimir Tokarev of Cyera and Sujal Tuladhar (EvilGenius) for bringing this issue to our attention and following the highest standards of coordinated disclosure.
.