Junglewise Threat Intelligence

CVE-2026-78689: NGINX njs XML namespace parser out-of-bounds write

CVE-2026-78689 · Severity: high · CVSS 8.1 · Published 2026-09-02

Vendors: NGINX.

Executive brief

NGINX JavaScript (njs) module contains a memory corruption vulnerability in its XML processing that can be exploited by sending malicious SAML or XML messages. An attacker can crash NGINX worker processes or cause memory leaks, leading to service disruption. The NGINX SAML reference implementation is particularly affected, as it processes untrusted XML namespace prefixes before verifying message signatures.

Technical details

The vulnerability is an out-of-bounds write in the XML module's namespace prefix list parser, reachable via the xml.exclusiveC14n() method. When an externally controlled XML namespace prefix list is passed to this method, a crafted prefix causes a heap buffer overflow. With the njs engine (default), this corrupts adjacent heap objects and crashes the worker; with QuickJS engine, it additionally leaks memory on each call. The nginxinc/nginx-saml reference implementation is affected because it reads the InclusiveNamespaces/@PrefixList from untrusted SAML messages and passes it to xml.exclusiveC14n() before signature verification. No authentication is required; network-reachable via SAML/XML processing. Code execution has not been demonstrated but cannot be ruled out depending on platform-specific memory layout conditions.

Affected products

  • NGINX njs all versions with XML module
  • NGINX nginx-saml reference implementation affected

Timeline

  • 2026-09-02: disclosed: Advisory published