Njs
Vendor:
First CVE: May 9, 2019 · Active for 7 years
40
Total CVEs
More Total CVEs than 97% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Njs over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2019
7 years ago
Most Recent CVE
May 19, 2026
68 days ago
CVE Severity & Scoring
Njs40 CVEs
23%
40%
38%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (22.5%)
Network31 (77.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None33 (82.5%)
Unknown0 (0.0%)
Required7 (17.5%)
Privileges Required
Low3 (7.5%)
High0 (0.0%)
None37 (92.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8711CRITICAL NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) an | May 19, 2026 | 9.8 | 44 | NO | NO |
CVE-2022-43286CRITICAL Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c. | Oct 28, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-27007CRITICAL nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). | Apr 14, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-13067CRITICAL njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place. | Jun 30, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-12208CRITICAL njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c. | May 20, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-12207CRITICAL njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. | May 20, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-11838CRITICAL njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of nj | May 9, 2019 | 9.8 | 32 | NO | NO |
CVE-2022-25139CRITICAL njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. | Feb 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-46463CRITICAL njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then(). | Feb 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-19695CRITICAL Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function. | Apr 4, 2023 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Njs
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.7.7 | 1 | 5.5 | 0.3% | 0 | 0 |
| 0.7.5 | 4 | 7.5 | 0.9% | 0 | 0 |
| 0.7.4 | 3 | 8.0 | 0.9% | 0 | 0 |
| 0.7.3 | 1 | 9.8 | 1.7% | 0 | 0 |
| 0.7.2 | 8 | 7.1 | 1.0% | 0 | 0 |
| 0.7.10 | 4 | 7.5 | 0.7% | 0 | 0 |