CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-18149 MEDIUM

undici vulnerable to Denial of Service via orphaned RetryHandler response body

CVSS 5.9 EPSS 0.36% Sep 4, 2026
npm
CVE-2026-18540 LOW

undici vulnerable to downstream response splitting via retry interceptor

CVSS 3.7 EPSS 0.24% Sep 4, 2026
npm
CVE-2026-19534 HIGH

undici vulnerable to Denial of Service via unrequested WebSocket subprotocol

CVSS 7.5 EPSS 0.39% Sep 4, 2026
npm
CVE-2026-84890 MEDIUM

undici vulnerable to Denial of Service via unbounded decompression of compressed responses

CVSS 5.9 EPSS 0.41% Sep 4, 2026
npm
CVE-2026-84933 HIGH

undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches

CVSS 8.2 EPSS 0.30% Sep 4, 2026
npm
CVE-2026-84947 MEDIUM

undici vulnerable to response truncation via oversized chunked responses in the dump interceptor

CVSS 6.5 EPSS 0.20% Sep 4, 2026
npm
CVE-2026-84961 CRITICAL

undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool

CVSS 9.1 EPSS 0.15% Sep 4, 2026
npm
CVE-2026-85008 MEDIUM

undici vulnerable to caching and replay of unsafe HTTP method responses

CVSS 5.3 EPSS 0.12% Sep 4, 2026
npm
CVE-2026-85152 HIGH

undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors

CVSS 7.4 EPSS 0.21% Sep 4, 2026
npm
CVE-2026-85014 HIGH

undici vulnerable to Denial of Service via WebSocketStream unclean close

CVSS 7.5 EPSS 0.37% Sep 4, 2026
npm
CVE-2026-85024 MEDIUM

undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression

CVSS 5.9 EPSS 0.41% Sep 4, 2026
npm
CVE-2026-48932 LOW

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `Incomi…

CVSS 3.7 EPSS 0.27% Sep 1, 2026
CVE-2026-56848 HIGH

nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service

CVSS 7.5 EPSS 0.49% Aug 4, 2026
CVE-2026-58042 MEDIUM

nodejs: Node.js: Denial of Service via DNS responses with excessive A records

CVSS 5.9 EPSS 0.37% Aug 4, 2026
CVE-2026-56846 HIGH

nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks

CVSS 7.5 EPSS 0.50% Aug 4, 2026
CVE-2026-58044 MEDIUM

nodejs: Node.js: Request smuggling via HTTP client header truncation

CVSS 4.8 EPSS 0.27% Aug 4, 2026
CVE-2026-58045 MEDIUM

nodejs: Node.js: Denial of Service vulnerability

CVSS 6.2 EPSS 0.17% Aug 4, 2026
CVE-2026-58041 MEDIUM

nodejs: Node.js node:sqlite: Unintended data modification due to stale statement iterator

CVSS 5.3 EPSS 0.29% Aug 4, 2026
CVE-2026-58039 MEDIUM

nodejs: Information disclosure due to improper permission enforcement

CVSS 4.4 EPSS 0.15% Jul 31, 2026
CVE-2026-56847 MEDIUM

nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions

CVSS 6.1 EPSS 0.16% Jul 30, 2026
CVE-2026-58043 HIGH

nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw

CVSS 8.4 EPSS 0.15% Jul 30, 2026
CVE-2026-56850 MEDIUM

nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw

CVSS 4.4 EPSS 0.08% Jul 30, 2026
CVE-2026-58040 MEDIUM

nodejs: HTTPS Agent TLS session reuse skips hostname verification

CVSS 6.3 EPSS 0.30% Jul 30, 2026
CVE-2026-15157 MEDIUM

undici vulnerable to CRLF Injection via blob-like body 'type' property

CVSS 5.4 EPSS 0.19% Jul 29, 2026
npm
CVE-2026-14643 HIGH

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

CVSS 7.5 EPSS 0.40% Jul 29, 2026
npm

Showing 1 to 25 CVEs · page 1 (more available)