{"id":"CVE-2022-29379","details":"Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release","modified":"2026-08-12T13:32:33.279091Z","published":"2022-05-25T12:56:33Z","database_specific":{"cna_assigner":"mitre","isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29379.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29379.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29379"},{"type":"REPORT","url":"https://github.com/nginx/njs/issues/491"},{"type":"REPORT","url":"https://github.com/nginx/njs/issues/493"},{"type":"FIX","url":"https://github.com/nginx/njs/commit/ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nginx/njs","events":[{"introduced":"b29a97464a46644005aed24b803e70ecf8e3f8fe"},{"fixed":"ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1"}],"database_specific":{"cpe":"cpe:2.3:a:f5:njs:0.7.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.7.3"},{"last_affected":"0.7.3"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.7.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29379.json","vanir_signatures_modified":"2026-08-12T13:32:33Z","vanir_signatures":[{"id":"CVE-2022-29379-44270a4c","signature_type":"Function","signature_version":"v1","source":"https://github.com/nginx/njs/commit/ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1","target":{"file":"src/njs_module.c","function":"njs_module_path"},"deprecated":false,"digest":{"function_hash":"248086882674698133665043392765408486192","length":1011}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/nginx/njs/commit/ab1702c7af9959366a5ddc4a75b4357d4e9ebdc1","target":{"file":"src/njs_module.c"},"deprecated":false,"digest":{"line_hashes":["7482429832924647298072604975357235335","269769495447719256786790798903243586245","87101805687335253733718727200713835148","149793166008216924919036397748877764215"],"threshold":0.9},"id":"CVE-2022-29379-f4471404"}]}}],"schema_version":"1.9.0"}