{"id":"AZL-99300","summary":"CVE-2026-78222 affecting package nginx 1.28.3-8","details":"A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","modified":"2026-09-05T14:17:01.850737021Z","published":"2026-09-02T16:17:23Z","upstream":["CVE-2026-78222"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78222"}],"affected":[{"package":{"name":"nginx","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/nginx"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.28.3-8"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99300.json"}}],"schema_version":"1.9.0"}