CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
undici vulnerable to Denial of Service via orphaned RetryHandler response body
undici vulnerable to downstream response splitting via retry interceptor
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
undici vulnerable to caching and replay of unsafe HTTP method responses
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
undici vulnerable to Denial of Service via WebSocketStream unclean close
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `Incomi…
nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service
nodejs: Node.js: Denial of Service via DNS responses with excessive A records
nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks
nodejs: Node.js: Request smuggling via HTTP client header truncation
nodejs: Node.js: Denial of Service vulnerability
nodejs: Node.js node:sqlite: Unintended data modification due to stale statement iterator
nodejs: Information disclosure due to improper permission enforcement
nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions
nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw
nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw
nodejs: HTTPS Agent TLS session reuse skips hostname verification
undici vulnerable to CRLF Injection via blob-like body 'type' property
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Showing 1 to 25 CVEs · page 1 (more available)