Njs

Vendor:

First CVE: May 9, 2019 · Active for 7 years

40
Total CVEs
More Total CVEs than 97% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Njs over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2019
7 years ago
Most Recent CVE
May 19, 2026
68 days ago

CVE Severity & Scoring

Njs40 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local9 (22.5%)
Network31 (77.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None33 (82.5%)
Unknown0 (0.0%)
Required7 (17.5%)
Privileges Required
Low3 (7.5%)
High0 (0.0%)
None37 (92.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) an
May 19, 20269.844NONO
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.
Oct 28, 20229.832NONO
nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save().
Apr 14, 20229.832NONO
njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.
Jun 30, 20199.832NONO
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c.
May 20, 20199.832NONO
njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.
May 20, 20199.832NONO
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of nj
May 9, 20199.832NONO
njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
Feb 14, 20229.831NONO
njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then().
Feb 14, 20229.831NONO
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
Apr 4, 20239.830NONO

Exploit Exposure

Signals from CVEs in this product scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (40 CVEs).

Media Mentions

Signals from CVEs in this product scope (40 CVEs).

Top CNAs Publishing CVEs For Njs

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.7.715.50.3%00
0.7.547.50.9%00
0.7.438.00.9%00
0.7.319.81.7%00
0.7.287.11.0%00
0.7.1047.50.7%00