Vulnerabilities in NodeJS

135 results
Vexday analysis

Com 75 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o Node.js apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica pressão ofensiva reduzida no momento. Ainda assim, o score EPSS de 0,8721 associado a CVE-2024-27983 merece atenção prioritária, pois sugere alta probabilidade de exploração calculada por modelos preditivos, mesmo sem confirmação ativa registrada. O tipo de falha mais recorrente é CWE-444 (inconsistência na interpretação de requisições HTTP), categoria que historicamente favorece ataques de request smuggling e bypass de controles intermediários. Com duas CVEs de severidade crítica no inventário e nenhum PoC público conhecido, o risco imediato é moderado, mas CVE-2024-27983 deve ser tratada como prioridade de remediação dado seu perfil de probabilidade elevada.

CVE-2024-22025MEDIUMA vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetEPSS 1.3%CVE-2023-46809HIGHNode.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched areEPSS 1.3%CVE-2022-35948MEDIUMCRLF Injection in Nodejs ‘undici’ via Content-TypeEPSS 1.3%CVE-2024-21896HIGHThe permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path isEPSS 1.3%CVE-2024-21891HIGHNode.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-dEPSS 1.2%CVE-2023-45143LOWUndici's cookie header not cleared on cross-origin redirect in fetchEPSS 1.2%CVE-2025-27209HIGHThe V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HasEPSS 1.2%CVE-2023-32003MEDIUM`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from EPSS 1.2%CVE-2023-30588When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs makiEPSS 1.2%CVE-2024-27982MEDIUMThe team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to EPSS 1.2%CVE-2026-21637MEDIUMA flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallbaEPSS 1.1%CVE-2023-23936MEDIUMCRLF Injection in Nodejs ‘undici’ via hostEPSS 1.1%CVE-2023-38552When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation aEPSS 1.1%CVE-2024-22020MEDIUMA security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can eEPSS 1.1%CVE-2024-36138HIGHBypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via childEPSS 1.1%CVE-2023-30581HIGHThe use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.jsoEPSS 1.1%CVE-2024-21890MEDIUMThe Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. EPSS 0.9%CVE-2023-39333MEDIUMMaliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data EPSS 0.9%CVE-2024-22017HIGHsetuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to performEPSS 0.9%CVE-2026-21636MEDIUMA flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enablEPSS 0.9%