
[CIVN-2026-0277] Remote Code Execution Vulnerability in NGINX
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in NGINX
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
NGINX JavaScript module (njs) versions 0.9.4 to 0.9.8
Overview
A vulnerability has been reported in the JavaScript module (njs) of NGINX, which could allow an unauthenticated attacker to execute arbitrary code, trigger denial of service (DoS) condition or a heap buffer overflow on the targeted system.
Target Audience:
All end user organizations and individuals using NGINX
Risk Assessment:
High risk of unauthorized access, system compromise.
Impact Assessment:
Potential for remote code execution, denial of service (DoS) condition, sensitive data exposure.
Description
NGINX is a high-performance web server, reverse proxy, load balancer and HTTP cache designed to handle massive, simultaneous connections with low resources usage. It acts as a fast, secure intermediary between clients and backend servers, serving static content, managing SSL/TLS encryption and distributing traffic to optimize speed.
A vulnerability exists in NGINX due to improper handling of client-controlled NGINX variables in the js_fetch_proxy directive when used with the ngx.fetch() operation in NGINX JavaScript. An attacker could exploit this by sending specially crafted HTTP requests.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code, trigger denial of service (DoS) condition or a heap buffer overflow on the targeted system.
Solution
Apply appropriate fix/patches as mentioned:
https://my.f5.com/manage/s/article/K000161307
Vendor Information
NGINX
https://my.f5.com/manage/s/article/K000161307
References
NGINX
https://my.f5.com/manage/s/article/K000161307
CVE Name
CVE-2026-8711
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogMswACgkQ3jCgcSdc
ys/AQBAAgnM9hke+sdvD06OVK4sMf876tLVPYBt4yoGC2IUimbRLJE2NGqOAyvTM
omAl7BI5jr+YE+ZvYSumfvEX0pVzDRL79rTMx6lmRiU9iWWZaIf0so09SnFD4kMx
O64ZjH4Gp6PU4LmIzToL7h9InbtYGSJYWXUEwZojfiiKV9Ay9x2lGPLc+LdFDyIg
l5YnXwhVsO5ejs5iW4het7aFCtJp4uJLDmtBgVRmVh+FIPb56z6+sZusK0U0kOEw
2coC4G4ECpIEfT5HXvvP6Jy+OjE46JJeUQ0BgLP/cw4a+hoWxXVdrh7vSNGJQxp8
Kors6HqDMFl7dzC4giY6X4iz0mlOu/cXDQJGzpZHsgcgUZJpTpM09HuLSvsCkYKv
qDfGajiuSkgV2/8r645F/Z7cjM0E3OB8wCf503pzhQBhnBDeCWNEPmCsFBRETYTs
KNCQ5OwPHB1swjJ5CWovI7MM7Rv5oh4x1mWnLCa6Gsh8wpstDpMeMN7Gt2Pew3KC
+MofNnyZEa2Mnq5IlS+th3JTQlgWwlgag1j1DC/8K6hljJ/PIkXjrMOgybKC0V+Q
BttUaYWB1r3uysRYIYtZ7xJIhUuLyR6+vXsBRhYMFQaSena2w+7FCp9bAGTnfeNm
eb3DbdH6ebJRMCTfBjfwz7kv+qd0/rhr0cPxYAXVE6TljWafa70=
=4hfw
—–END PGP SIGNATURE—–


