CVE-2020-19695: F5 Njs

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.

Affected products

  • F5 Njs: before 0.3.4 (fixed in 0.3.4)

Published 2023-04-04. Last modified 2026-06-17.