Nginx · Nginx Njs · CVE-2022-28049
**Name of the Vulnerable Software and Affected Versions**
NGINX NJS version 0.7.2
**Description**
The issue is related to a NULL pointer dereference via the `njs vmcode array` component at `/src/njs vmcode.c`. This can potentially allow a remote attacker to cause a denial of service.
**Recommendations**
For NGINX NJS version 0.7.2, consider disabling the `njs vmcode array` component as a temporary workaround until a patch is available. Restrict access to the `/src/njs vmcode.c` component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.