CVE-2026-8711 (matched: nginx)

  • Thursday, 23rd July, 2026
  • 22:05pm

A security vulnerability has been identified in the NGINX JavaScript feature, a tool some websites use to add custom, dynamic functionality. This flaw only affects sites that meet two specific conditions: the js_fetch_proxy setting is configured to use at least one value controlled by website visitors (such as data from HTTP request headers, URL parameters, or browser cookies), and the site uses the ngx.fetch() operation from NGINX JavaScript. Unauthenticated attackers, who do not need any login credentials for your site, can exploit this flaw by sending specially crafted HTTP requests to your website. The most common impact is a crash and automatic restart of the NGINX worker process that handles your site's traffic, which can cause brief, unexpected downtime for your visitors. On servers where the Address Space Layout Randomization (ASLR) security feature is disabled or can be bypassed by an attacker, bad actors may also be able to run unauthorized code on the server. Software versions that have reached their End of Technical Support (EoTS) are not included in this vulnerability assessment.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-8711

« Back