PT-2022-12721 · Nginx · Njs

Afang5472

+2

·

Published

2022-02-14

·

Updated

2026-04-21

·

CVE-2021-46463

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions njs versions through 0.7.1
Description A control flow hijack was discovered in njs, caused by a Type Confusion vulnerability in the njs promise perform then() function. This issue affects njs used in NGINX.
Recommendations For versions through 0.7.1, consider disabling the njs promise perform then() function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AF45008
CLEANSTART-2026-BA37192
CLEANSTART-2026-MQ02912
CLEANSTART-2026-XB16901
CLEANSTART-2026-ZN32454
CLEANSTART-2026-ZT77083
CVE-2021-46463

Affected Products

Njs