Access control bypass in js_access when an asynchronous request
body continuation threw an exception or produced an unhandled
rejection (CVE-2026-18329). Previously, nginx could continue
processing the request as though the js_access check had
succeeded. Affects 0.9.9-1.0.0.
Worker process crash when reading Response.statusText after an
upstream server returned a status line with an empty reason
phrase (CVE-2026-78222). Affects 0.5.1-1.0.0.
Heap buffer overflow while parsing namespace prefix lists
passed to xml.exclusiveC14n() (CVE-2026-78689). Affects
0.7.10-1.0.0.