← Vulnerability feed

Vulnerability record · CVE-2026-8711 · published 19 May 2026

CVE-2026-8711: F5 njs heap-based buffer overflow vulnerability

F5 · Njs

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

9.2 CVSS 4.0 Critical EPSS 0.79% · top 45.5% CWE-122 · Heap-based buffer overflow
9.2CVSS 4.0 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-8711 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-19692F5 njs classic buffer overflow vulnerabilityBuffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_modul…EPSS 1.3%9.8CVE-2020-19695F5 njs classic buffer overflow vulnerabilityBuffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c funct…EPSS 1.3%9.8CVE-2022-43286F5 njs use after free vulnerabilityNginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at nj…EPSS 0.96%9.8CVE-2022-29379F5 njs out-of-bounds write vulnerabilityNginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple th…EPSS 1.8%9.8CVE-2022-27007F5 njs use after free vulnerabilitynginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_func…EPSS 1.6%9.8CVE-2022-25139F5 njs use after free vulnerabilitynjs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.EPSS 1.6%9.8CVE-2021-46463F5 njs type confusion vulnerabilitynjs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_the…EPSS 1.7%9.8CVE-2019-13067F5 njs out-of-bounds read vulnerabilitynjs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2026-8711), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.