← Vulnerability feed

Vulnerability record · CVE-2022-29379 · published 25 May 2022

CVE-2022-29379: F5 njs out-of-bounds write vulnerability

F5 · Njs

Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release

9.8 CVSS 3.1 Critical EPSS 1.8% · top 22.7% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/nginx/njs/commit/ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1 PatchThird Party Advisory
https://github.com/nginx/njs/issues/491 Issue TrackingThird Party Advisory
https://github.com/nginx/njs/issues/493 ExploitIssue TrackingPatchThird Party Advisory
https://github.com/nginx/njs/commit/ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1 PatchThird Party Advisory
https://github.com/nginx/njs/issues/491 Issue TrackingThird Party Advisory
https://github.com/nginx/njs/issues/493 ExploitIssue TrackingPatchThird Party Advisory

Track CVE-2022-29379 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-19692F5 njs classic buffer overflow vulnerabilityBuffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_modul…EPSS 1.3%9.8CVE-2020-19695F5 njs classic buffer overflow vulnerabilityBuffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c funct…EPSS 1.3%9.8CVE-2022-43286F5 njs use after free vulnerabilityNginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at nj…EPSS 0.96%9.8CVE-2022-27007F5 njs use after free vulnerabilitynginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_func…EPSS 1.6%9.8CVE-2022-25139F5 njs use after free vulnerabilitynjs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.EPSS 1.6%9.8CVE-2021-46463F5 njs type confusion vulnerabilitynjs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_the…EPSS 1.7%9.8CVE-2019-13067F5 njs out-of-bounds read vulnerabilitynjs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is …EPSS 1.6%9.8CVE-2019-12206F5 njs out-of-bounds write vulnerabilitynjs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c.EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2022-29379), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.