Vulnerabilidades em NodeJS

135 resultados
Análise Vexday

Com 75 CVEs catalogadas e nenhuma atualmente listada no catálogo KEV da CISA, o Node.js apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica pressão ofensiva reduzida no momento. Ainda assim, o score EPSS de 0,8721 associado a CVE-2024-27983 merece atenção prioritária, pois sugere alta probabilidade de exploração calculada por modelos preditivos, mesmo sem confirmação ativa registrada. O tipo de falha mais recorrente é CWE-444 (inconsistência na interpretação de requisições HTTP), categoria que historicamente favorece ataques de request smuggling e bypass de controles intermediários. Com duas CVEs de severidade crítica no inventário e nenhum PoC público conhecido, o risco imediato é moderado, mas CVE-2024-27983 deve ser tratada como prioridade de remediação dado seu perfil de probabilidade elevada.

CVE-2023-23918HIGHA privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimeEPSS 2.0%CVE-2022-35255CRITICALA weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGeEPSS 1.9%CVE-2023-39332Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class exEPSS 1.8%CVE-2023-32559HIGHA privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use EPSS 1.8%CVE-2022-35949MEDIUM`undici.request` vulnerable to SSRF using absolute URL on `pathname`EPSS 1.8%CVE-2022-32223Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploiEPSS 1.8%CVE-2023-32558The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. This vulnerability affects all uEPSS 1.7%CVE-2025-55130HIGHA flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativEPSS 1.7%CVE-2023-32002CRITICALThe use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. TEPSS 1.6%CVE-2025-23084MEDIUMA vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.EPSS 1.6%CVE-2023-32006HIGHThe use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition foEPSS 1.5%CVE-2023-30585A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows users who install NodEPSS 1.5%CVE-2023-30590The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generEPSS 1.5%CVE-2022-31150MEDIUMCRLF injection in request headersEPSS 1.4%CVE-2024-27980HIGHDue to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject aEPSS 1.4%CVE-2025-23085MEDIUMA memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid hEPSS 1.4%CVE-2023-32005MEDIUMA vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flaEPSS 1.4%CVE-2023-30586HIGHA privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission moEPSS 1.3%CVE-2023-39331HIGHA previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability ariEPSS 1.3%CVE-2023-24807HIGHUndici vulnerable to Regular Expression Denial of Service in HeadersEPSS 1.3%