← Vulnerability feed

Vulnerability record · CVE-2019-13067 · published 30 June 2019

CVE-2019-13067: F5 njs out-of-bounds read vulnerability

F5 · Njs

njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.

9.8 CVSS 3.0 Critical EPSS 1.6% · top 25.2% CWE-125 · Out-of-bounds read
9.8CVSS 3.0 base score, v2 7.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/nginx/njs/issues/183 ExploitIssue TrackingThird Party Advisory
https://github.com/nginx/njs/issues/183 ExploitIssue TrackingThird Party Advisory

Track CVE-2019-13067 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-19692F5 njs classic buffer overflow vulnerabilityBuffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_modul…EPSS 1.3%9.8CVE-2020-19695F5 njs classic buffer overflow vulnerabilityBuffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c funct…EPSS 1.3%9.8CVE-2022-43286F5 njs use after free vulnerabilityNginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at nj…EPSS 0.96%9.8CVE-2022-29379F5 njs out-of-bounds write vulnerabilityNginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple th…EPSS 1.8%9.8CVE-2022-27007F5 njs use after free vulnerabilitynginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_func…EPSS 1.6%9.8CVE-2022-25139F5 njs use after free vulnerabilitynjs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.EPSS 1.6%9.8CVE-2021-46463F5 njs type confusion vulnerabilitynjs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_the…EPSS 1.7%9.8CVE-2019-12206F5 njs out-of-bounds write vulnerabilitynjs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c.EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2019-13067), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.