[CIVN-2026-0277] Remote Code Execution Vulnerability in NGINX

By Published On: June 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Remote Code Execution Vulnerability in NGINX


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


NGINX JavaScript module (njs) versions 0.9.4 to 0.9.8

Overview


A vulnerability has been reported in the JavaScript module (njs) of NGINX, which could allow an unauthenticated attacker to execute arbitrary code, trigger denial of service (DoS) condition or a heap buffer overflow on the targeted system.


Target Audience:

All end user organizations and individuals using NGINX


Risk Assessment: 

High risk of unauthorized access, system compromise.


Impact Assessment:

Potential for remote code execution, denial of service (DoS) condition, sensitive data exposure.


Description


NGINX is a high-performance web server, reverse proxy, load balancer and HTTP cache designed to handle massive, simultaneous connections with low resources usage. It acts as a fast, secure intermediary between clients and backend servers, serving static content, managing SSL/TLS encryption and distributing traffic to optimize speed.


A vulnerability exists in NGINX due to improper handling of client-controlled NGINX variables in the js_fetch_proxy directive when used with the ngx.fetch() operation in NGINX JavaScript. An attacker could exploit this by sending specially crafted HTTP requests.


Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code, trigger denial of service (DoS) condition or a heap buffer overflow on the targeted system.


Solution


Apply appropriate fix/patches as mentioned:

https://my.f5.com/manage/s/article/K000161307



Vendor Information


NGINX

https://my.f5.com/manage/s/article/K000161307


References


NGINX

https://my.f5.com/manage/s/article/K000161307


CVE Name

CVE-2026-8711




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogMswACgkQ3jCgcSdc

ys/AQBAAgnM9hke+sdvD06OVK4sMf876tLVPYBt4yoGC2IUimbRLJE2NGqOAyvTM

omAl7BI5jr+YE+ZvYSumfvEX0pVzDRL79rTMx6lmRiU9iWWZaIf0so09SnFD4kMx

O64ZjH4Gp6PU4LmIzToL7h9InbtYGSJYWXUEwZojfiiKV9Ay9x2lGPLc+LdFDyIg

l5YnXwhVsO5ejs5iW4het7aFCtJp4uJLDmtBgVRmVh+FIPb56z6+sZusK0U0kOEw

2coC4G4ECpIEfT5HXvvP6Jy+OjE46JJeUQ0BgLP/cw4a+hoWxXVdrh7vSNGJQxp8

Kors6HqDMFl7dzC4giY6X4iz0mlOu/cXDQJGzpZHsgcgUZJpTpM09HuLSvsCkYKv

qDfGajiuSkgV2/8r645F/Z7cjM0E3OB8wCf503pzhQBhnBDeCWNEPmCsFBRETYTs

KNCQ5OwPHB1swjJ5CWovI7MM7Rv5oh4x1mWnLCa6Gsh8wpstDpMeMN7Gt2Pew3KC

+MofNnyZEa2Mnq5IlS+th3JTQlgWwlgag1j1DC/8K6hljJ/PIkXjrMOgybKC0V+Q

BttUaYWB1r3uysRYIYtZ7xJIhUuLyR6+vXsBRhYMFQaSena2w+7FCp9bAGTnfeNm

eb3DbdH6ebJRMCTfBjfwz7kv+qd0/rhr0cPxYAXVE6TljWafa70=

=4hfw

—–END PGP SIGNATURE—–

Share this article