SecurityHorrors

Stories you never want to feel on your own skin

20 May 2026

NGINX njs: One Overflow to Crash Them All

TLDR and affected version summary for CVE-2026-8711, a heap buffer overflow in NGINX JavaScript (njs) that can crash workers and may allow RCE.