PatchSiren cyber security CVE debrief
CVE-2026-18329 F5 CVE debrief
The CVE-2026-18329 vulnerability affects NGINX JavaScript (njs) and QuickJS (qjs) engines, which are components used for handling JavaScript in NGINX. This vulnerability class involves asynchronous request body processing and access-control evaluation. An unauthenticated attacker can exploit this by sending a crafted HTTP request that triggers an error condition in the access validation logic, potentially causing the js_access phase to fail open. This could allow the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources. Users should review their exposure and update their systems to the latest version. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Vendor
- F5
- Product
- NGINX JavaScript
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Users of NGINX JavaScript (njs) and QuickJS (qjs) engines should review and update their systems to the latest version. Additionally, implement compensating controls to monitor and restrict access to protected resources.
Technical summary
The CVE-2026-18329 vulnerability affects NGINX JavaScript (njs) and QuickJS (qjs) engines. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources.
Defensive priority
NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability that may allow remote attackers to bypass js_access controls. This is a data plane issue only with no control plane exposure.
Recommended defensive actions
- Review and update NGINX JavaScript (njs) and QuickJS (qjs) engines to the latest version.
- Implement compensating controls to monitor and restrict access to protected resources.
- Perform inventory checks to identify and address potential vulnerabilities in the environment.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-18329 vulnerability affects NGINX JavaScript (njs) and QuickJS (qjs) engines. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources. Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18329 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18329
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18329 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18329
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://my.f5.com/manage/s/article/K000162599
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.