Vulnerabilities in NodeJS

135 results
Vexday analysis

Com 75 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o Node.js apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica pressão ofensiva reduzida no momento. Ainda assim, o score EPSS de 0,8721 associado a CVE-2024-27983 merece atenção prioritária, pois sugere alta probabilidade de exploração calculada por modelos preditivos, mesmo sem confirmação ativa registrada. O tipo de falha mais recorrente é CWE-444 (inconsistência na interpretação de requisições HTTP), categoria que historicamente favorece ataques de request smuggling e bypass de controles intermediários. Com duas CVEs de severidade crítica no inventário e nenhum PoC público conhecido, o risco imediato é moderado, mas CVE-2024-27983 deve ser tratada como prioridade de remediação dado seu perfil de probabilidade elevada.

CVE-2026-48934MEDIUMA flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supporteEPSS 0.3%CVE-2026-58041MEDIUMA flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cacEPSS 0.3%CVE-2026-58044LOWA flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from EPSS 0.2%CVE-2026-48928MEDIUMA inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects allEPSS 0.2%CVE-2026-48935LOWA flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-reaEPSS 0.2%CVE-2026-21711MEDIUMA flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission cheEPSS 0.2%CVE-2026-48932LOWA flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from EPSS 0.2%CVE-2026-58045MEDIUMA flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing tEPSS 0.2%CVE-2026-21715LOWA flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, whiEPSS 0.2%CVE-2026-56847LOWA flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. EPSS 0.2%CVE-2026-58039LOWA flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This canEPSS 0.2%CVE-2026-21716LOWAn incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permissioEPSS 0.1%CVE-2026-58043HIGHA flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`EPSS 0.1%CVE-2026-48936LOWA flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permissioEPSS 0.1%CVE-2026-56850MEDIUMA flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to beEPSS 0.1%