FeedNew NGINX Vulnerability Allows Remote Attackers to Trigger M...
Cyber Security News

New NGINX Vulnerability Allows Remote Attackers to Trigger Malicious Code

📅 20 May 2026 at 08:57 UTC📰 Cyber Security NewsView original source ↗
New NGINX Vulnerability Allows Remote Attackers to Trigger Malicious Code

A new vulnerability in NGINX JavaScript (njs), tracked as CVE‑2026‑8711, allows unauthenticated remote attackers to trigger a heap‑based buffer overflow that can lead to denial‑of‑service and, in some conditions, remote code execution in the NGINX worker process. The flaw is tied to how the js_fetch_proxy directive handles client‑controlled variables when combined with the ngx.fetch() operation […] The post New NGINX Vulnerability Allows Remote Attackers to Trigger Malicious Code appeared first on Cyber Security News.

Read the full article

This is a curated summary. The complete article is available at Cyber Security News.

Read on Cyber Security News
← Back to feed