Junglewise Threat Intelligence

CVE-2026-78222: NGINX JavaScript crash in ngx.fetch() response handling

CVE-2026-78222 · Severity: high · CVSS 7.5 · Published 2026-09-02

Vendors: NGINX.

Executive brief

NGINX JavaScript contains a vulnerability where malformed HTTP responses can crash worker processes when trusted JavaScript code accesses the Response.statusText property. An attacker who can influence the HTTP response returned by ngx.fetch() can trigger a denial-of-service condition affecting NGINX availability.

Technical details

The vulnerability exists in NGINX JavaScript's handling of malformed HTTP responses received via ngx.fetch(). When trusted JavaScript code attempts to read the Response.statusText property from a specially crafted response, an unhandled exception or memory corruption occurs, crashing the NGINX worker process. This is a data plane vulnerability with no control plane exposure. Exploitation requires an attacker to control or influence the HTTP response being fetched, making this a network-accessible denial-of-service vector. No patch information is currently available in the advisory.

Affected products

  • NGINX NGINX JavaScript

Timeline

  • 2026-09-02: disclosed

References