FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

angie-module-njs -- multiple vulnerabilities

Affected packages
angie-module-njs < 1.0.1,1

Details

VuXML ID 6cf326a2-b38c-11f1-a655-3497f65b111b
Discovery 2026-09-02
Entry 2026-09-18

The njs development team reports:

Access control bypass in js_access when an asynchronous request body continuation threw an exception or produced an unhandled rejection (CVE-2026-18329). Previously, nginx could continue processing the request as though the js_access check had succeeded. Affects 0.9.9-1.0.0.

Worker process crash when reading Response.statusText after an upstream server returned a status line with an empty reason phrase (CVE-2026-78222). Affects 0.5.1-1.0.0.

Heap buffer overflow while parsing namespace prefix lists passed to xml.exclusiveC14n() (CVE-2026-78689). Affects 0.7.10-1.0.0.

References

CVE Name CVE-2026-18329
CVE Name CVE-2026-78222
CVE Name CVE-2026-78689
URL https://nginx.org/en/docs/njs/changes.html#njs1.0.1
URL https://nginx.org/en/docs/njs/security.html#advisories