Vulnerabilities in nodejs
134 resultsVexday analysis
Node.js apresenta 48 vulnerabilidades catalogadas na base, com 12 divulgadas nos últimos 90 dias, indicando atividade recente de descoberta de falhas. Nenhuma CVE está sob exploração ativa (KEV) nem classificada como crítica, reduzindo o risco imediato. A fraqueza dominante (CWE-284) aponta problemas de controle de acesso, sugerindo que a maior parte dos riscos reside em cenários de escalação de privilégio ou autorização inadequada.
CVE-2023-23920MEDIUMAn untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search aEPSS 0.5%CVE-2025-23167MEDIUMA flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`.
This inEPSS 0.5%CVE-2024-22018LOWA vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used.
EPSS 0.5%CVE-2026-21714MEDIUMA memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow cEPSS 0.5%CVE-2026-22036MEDIUMUndici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionEPSS 0.4%CVE-2026-48615MEDIUMA flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.
When proxy credentialsEPSS 0.4%CVE-2025-23083HIGHWith the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only tEPSS 0.4%CVE-2026-58042MEDIUMA flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.
Repeated trEPSS 0.4%CVE-2024-36137LOWA vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used.EPSS 0.4%CVE-2026-21713MEDIUMA flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timingEPSS 0.4%CVE-2023-30584HIGHA vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improEPSS 0.4%CVE-2026-48931LOWA flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.
This vEPSS 0.3%CVE-2026-21712MEDIUMA flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalizedEPSS 0.3%CVE-2026-48930MEDIUMA flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation iEPSS 0.3%CVE-2026-58041MEDIUMA flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cacEPSS 0.3%CVE-2026-21717MEDIUMA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially prEPSS 0.3%CVE-2026-58044LOWA flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from EPSS 0.3%CVE-2025-47279LOWundici Denial of Service attack via bad certificate dataEPSS 0.3%CVE-2026-58040MEDIUMAn incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incompEPSS 0.3%CVE-2026-48934MEDIUMA flaw in Node.js TLS host verification can cause an attacker to bypass certification validation.
This vulnerability affects all supporteEPSS 0.3%