Executive brief
NGINX JavaScript contains a vulnerability where malformed HTTP responses can crash worker processes when trusted JavaScript code accesses the Response.statusText property. An attacker who can influence the HTTP response returned by ngx.fetch() can trigger a denial-of-service condition affecting NGINX availability.
Technical details
The vulnerability exists in NGINX JavaScript's handling of malformed HTTP responses received via ngx.fetch(). When trusted JavaScript code attempts to read the Response.statusText property from a specially crafted response, an unhandled exception or memory corruption occurs, crashing the NGINX worker process. This is a data plane vulnerability with no control plane exposure. Exploitation requires an attacker to control or influence the HTTP response being fetched, making this a network-accessible denial-of-service vector. No patch information is currently available in the advisory.
Affected products
- NGINX NGINX JavaScript
Timeline
- 2026-09-02: disclosed