FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

njs -- heap buffer overflow in XML exclusive canonicalization

Affected packages
libnjs < 1.0.1
nginx-module-njs < 1.0.1
njs < 1.0.1
nginx-full < 1.30.4_7,3

Details

VuXML ID 0bfb082c-a7b6-11f1-a655-3497f65b111b
Discovery 2026-09-02
Entry 2026-09-03

F5 reports:

A flaw in the NGINX JavaScript XML module allows an out-of-bounds write when xml.exclusiveC14n() processes a crafted XML namespace prefix list. This may lead to worker process crashes, heap corruption or memory disclosure. The NGINX SAML reference implementation is affected because it processes SAML data before signature verification.

References

CVE Name CVE-2026-78689
URL https://my.f5.com/manage/s/article/K000162602
URL https://nginx.org/en/docs/njs/changes.html