Vulnerabilities in NodeJS

135 results
Vexday analysis

Com 75 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o Node.js apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica pressão ofensiva reduzida no momento. Ainda assim, o score EPSS de 0,8721 associado a CVE-2024-27983 merece atenção prioritária, pois sugere alta probabilidade de exploração calculada por modelos preditivos, mesmo sem confirmação ativa registrada. O tipo de falha mais recorrente é CWE-444 (inconsistência na interpretação de requisições HTTP), categoria que historicamente favorece ataques de request smuggling e bypass de controles intermediários. Com duas CVEs de severidade crítica no inventário e nenhum PoC público conhecido, o risco imediato é moderado, mas CVE-2024-27983 deve ser tratada como prioridade de remediação dado seu perfil de probabilidade elevada.

CVE-2025-23166HIGHThe C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background tEPSS 0.8%CVE-2024-30261LOWUndici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrectEPSS 0.8%CVE-2024-24758LOWProxy-Authorization header not cleared on cross-origin redirect in fetch in UndiciEPSS 0.8%CVE-2025-22150MEDIUMUndici Uses Insufficiently Random ValuesEPSS 0.8%CVE-2023-30587HIGHA vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspectEPSS 0.7%CVE-2024-30260LOWUndici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelineEPSS 0.7%CVE-2023-30583HIGHfs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in EPSS 0.7%CVE-2022-31151LOWUncleared cookies on cross-host/cross-origin redirect in undiciEPSS 0.7%CVE-2020-8252The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which EPSS 0.7%CVE-2024-24750MEDIUMBackpressure request ignored in fetch() in UndiciEPSS 0.7%CVE-2025-59466MEDIUMWe have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.creaEPSS 0.7%CVE-2026-48619MEDIUMA flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on EPSS 0.6%CVE-2023-30582MEDIUMA vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flaEPSS 0.6%CVE-2026-48937MEDIUMA flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affectsEPSS 0.6%CVE-2024-21892HIGHOn Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running withEPSS 0.6%CVE-2025-23165LOWIn Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocatedEPSS 0.6%CVE-2025-23167MEDIUMA flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inEPSS 0.5%CVE-2026-56846HIGHA flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. ThiEPSS 0.5%CVE-2026-56848HIGHA flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executEPSS 0.5%CVE-2024-37372LOWThe Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not alwEPSS 0.5%