Vulnerabilities in nodejs

134 results
Vexday analysis

Node.js apresenta 48 vulnerabilidades catalogadas na base, com 12 divulgadas nos últimos 90 dias, indicando atividade recente de descoberta de falhas. Nenhuma CVE está sob exploração ativa (KEV) nem classificada como crítica, reduzindo o risco imediato. A fraqueza dominante (CWE-284) aponta problemas de controle de acesso, sugerindo que a maior parte dos riscos reside em cenários de escalação de privilégio ou autorização inadequada.

CVE-2026-48617LOWA flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confideEPSS 0.2%CVE-2025-59464MEDIUMA memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffEPSS 0.2%CVE-2025-55132LOWA flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process EPSS 0.2%CVE-2026-48928MEDIUMA inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects allEPSS 0.2%CVE-2026-58045MEDIUMA flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing tEPSS 0.2%CVE-2026-48935LOWA flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-reaEPSS 0.2%CVE-2026-58039LOWA flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This canEPSS 0.2%CVE-2026-21716LOWAn incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permissioEPSS 0.2%CVE-2026-21715LOWA flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, whiEPSS 0.2%CVE-2026-56847LOWA flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. EPSS 0.2%CVE-2026-48936LOWA flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permissioEPSS 0.2%CVE-2026-21711MEDIUMA flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission cheEPSS 0.1%CVE-2026-58043HIGHA flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`EPSS 0.1%CVE-2026-56850MEDIUMA flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to beEPSS 0.1%