Vulnerabilidades em nodejs

134 resultados
Análise Vexday

Node.js apresenta 48 vulnerabilidades catalogadas na base, com 12 divulgadas nos últimos 90 dias, indicando atividade recente de descoberta de falhas. Nenhuma CVE está sob exploração ativa (KEV) nem classificada como crítica, reduzindo o risco imediato. A fraqueza dominante (CWE-284) aponta problemas de controle de acesso, sugerindo que a maior parte dos riscos reside em cenários de escalação de privilégio ou autorização inadequada.

CVE-2025-27209HIGHThe V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HasEPSS 0.8%CVE-2024-24758LOWProxy-Authorization header not cleared on cross-origin redirect in fetch in UndiciEPSS 0.8%CVE-2025-22150MEDIUMUndici Uses Insufficiently Random ValuesEPSS 0.7%CVE-2023-30587HIGHA vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspectEPSS 0.7%CVE-2024-30260LOWUndici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelineEPSS 0.7%CVE-2023-30583HIGHfs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in EPSS 0.7%CVE-2020-8252The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which EPSS 0.7%CVE-2022-31151LOWUncleared cookies on cross-host/cross-origin redirect in undiciEPSS 0.7%CVE-2024-24750MEDIUMBackpressure request ignored in fetch() in UndiciEPSS 0.7%CVE-2026-21636MEDIUMA flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enablEPSS 0.7%CVE-2026-48619MEDIUMA flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on EPSS 0.6%CVE-2025-59466MEDIUMWe have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.creaEPSS 0.6%CVE-2026-56846HIGHA flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. ThiEPSS 0.6%CVE-2026-56848HIGHA flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executEPSS 0.6%CVE-2023-30582MEDIUMA vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flaEPSS 0.6%CVE-2024-21892HIGHOn Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running withEPSS 0.6%CVE-2026-48937MEDIUMA flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affectsEPSS 0.5%CVE-2025-23165LOWIn Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocatedEPSS 0.5%CVE-2025-23167MEDIUMA flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inEPSS 0.5%CVE-2024-37372LOWThe Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not alwEPSS 0.5%