Vulnerabilidades en NodeJS

135 resultados
Análisis Vexday

Com 75 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o Node.js apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica pressão ofensiva reduzida no momento. Ainda assim, o score EPSS de 0,8721 associado a CVE-2024-27983 merece atenção prioritária, pois sugere alta probabilidade de exploração calculada por modelos preditivos, mesmo sem confirmação ativa registrada. O tipo de falha mais recorrente é CWE-444 (inconsistência na interpretação de requisições HTTP), categoria que historicamente favorece ataques de request smuggling e bypass de controles intermediários. Com duas CVEs de severidade crítica no inventário e nenhum PoC público conhecido, o risco imediato é moderado, mas CVE-2024-27983 deve ser tratada como prioridade de remediação dado seu perfil de probabilidade elevada.

CVE-2026-22036MEDIUMUndici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionEPSS 0.5%CVE-2023-23920MEDIUMAn untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search aEPSS 0.5%CVE-2024-38372LOWUndici vulnerable to data leak when using response.arrayBuffer()EPSS 0.5%CVE-2024-22018LOWA vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. EPSS 0.5%CVE-2026-21714MEDIUMA memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow cEPSS 0.5%CVE-2025-23083HIGHWith the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only tEPSS 0.4%CVE-2026-48615MEDIUMA flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentialsEPSS 0.4%CVE-2024-36137LOWA vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used.EPSS 0.4%CVE-2026-21713MEDIUMA flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timingEPSS 0.4%CVE-2023-30584HIGHA vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improEPSS 0.4%CVE-2026-58042MEDIUMA flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated trEPSS 0.4%CVE-2026-48931LOWA flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vEPSS 0.3%CVE-2026-48930MEDIUMA flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation iEPSS 0.3%CVE-2025-47279LOWundici Denial of Service attack via bad certificate dataEPSS 0.3%CVE-2026-21712MEDIUMA flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalizedEPSS 0.3%CVE-2026-48617LOWA flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confideEPSS 0.3%CVE-2026-58040MEDIUMAn incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incompEPSS 0.3%CVE-2026-21717MEDIUMA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially prEPSS 0.3%CVE-2025-59464MEDIUMA memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffEPSS 0.3%CVE-2025-55132LOWA flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process EPSS 0.3%