CVE-2026-78222

NameCVE-2026-78222
DescriptionA vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libnginx-mod-js (PTS)bookworm0.7.9-2vulnerable
trixie0.8.9-1vulnerable
forky, sid1.0.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libnginx-mod-jssource(unstable)1.0.1-1

Notes

[trixie] - libnginx-mod-js <no-dsa> (Minor issue)
https://my.f5.com/manage/s/article/K000162603
https://github.com/nginx/njs/commit/a62feb4831e75c75c446298ca4a23862dcfcbab4 (1.0.1)
https://github.com/nginx/njs/releases/tag/1.0.1

Search for package or bug name: Reporting problems