Known vulnerabilities in NGINX JavaScript
Vendor:
F5 Networks
Software:
NGINX JavaScript
Software CPE:
cpe:2.3:a:f5_networks:ngx_http_js_module:*:*:*:*:*:nginx:*:*
Website:
https://f5.com/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
1.0.1
1.0.0
0.8.10
0.8.9
0.8.8
0.8.7
0.8.6
0.8.5
0.8.4
0.8.3
0.8.2
0.8.1
0.8.0
0.7.12
0.7.11
0.7.10
0.7.9
0.7.8
0.7.7
0.7.6
0.7.5
0.7.4
0.7.3
0.7.2
0.7.1
0.7.0
0.6.2
0.6.1
0.6.0
0.5.3
0.5.2
0.5.1
0.5.0
0.4.4
0.4.3
0.4.2
0.4.1
0.4.0
0.3.9
0.3.8
0.3.7
0.3.6
0.3.5
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.8
0.2.7
0.2.6
0.2.5
0.2.4
0.2.3
0.2.2
0.2.1
0.2.0
0.1.15
0.1.14
0.1.13
0.1.12
0.1.11
0.1.10
0.1.9
0.1.8
0.1.7
0.1.6
0.1.5
0.1.4
0.1.3
0.1.2
0.1.1
0.1.0
0.9.9
0.9.8
0.9.7
0.9.6
0.9.5
0.9.4
0.9.3
0.9.2
0.9.1
0.9.0
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU147230 - Heap-based Buffer Overflow CVE-2026-78689 |
CWE-122 | High | 1.0.1 | 07.09.2026 |
SB2026090741 |
||
| #VU147229 - NULL Pointer Dereference CVE-2026-78222 |
CWE-476 | Medium | 1.0.1 | 07.09.2026 |
SB2026090741 |
||
| #VU147228 - Not Failing Securely (\'Failing Open\') CVE-2026-18329 |
CWE-636 | High | 1.0.1 | 07.09.2026 |
SB2026090741 |
||
| #VU131922 - Heap-based Buffer Overflow CVE-2026-8711 |
CWE-122 | High | 0.9.9 | 20.05.2026 |
SB2026052055 |