Vulnerabilities in feathersjs
6 resultsVexday analysis
FeathersJS apresenta um pequeno portfólio de 6 vulnerabilidades, com 1 crítica (CVSS ≥9.0) e nenhuma sob exploração ativa conhecida (KEV). A fraqueza dominante é CWE-1321, indicando problemas estruturais na validação ou tratamento de dados. O risco permanece contido, mas a publicação recente de 1 vulnerabilidade nos últimos 90 dias reforça a necessidade de monitoramento contínuo.
CVE-2023-37899HIGHfeathersjs socket handler allows abusing implicit toStringEPSS 1.2%CVE-2026-29792CRITICALFeathersjs has an OAuth Callback Account TakeoverEPSS 0.5%CVE-2026-54335LOWFeathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__EPSS 0.4%CVE-2026-27193HIGHFeathers exposes internal headers via unencrypted session cookieEPSS 0.4%CVE-2026-27191HIGHFeathers: Open Redirect in OAuth callback enables account takeoverEPSS 0.3%CVE-2026-27192HIGHFeathers has an origin validation bypass via prefix matchingEPSS 0.2%