SecurityHorrors

Stories you never want to feel on your own skin

20 May 2026

NGINX njs: One Overflow to Crash Them All

TLDR and affected version summary for CVE-2026-8711, a heap buffer overflow in NGINX JavaScript (njs) that can crash workers and may allow RCE.

13 May 2026

NGINX: Three Cracks in the Proxy Wall

TLDR and affected version summary for NGINX Rift, CVE-2026-42926, and CVE-2026-42946