Node.js / Node
74 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48932 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `Incomi… | LOW | 3.7 | Sep 1, 2026 |
| CVE-2026-56848 | nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service | HIGH | 7.5 | Aug 4, 2026 |
| CVE-2026-58042 | nodejs: Node.js: Denial of Service via DNS responses with excessive A records | MEDIUM | 5.9 | Aug 4, 2026 |
| CVE-2026-56846 | nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks | HIGH | 7.5 | Aug 4, 2026 |
| CVE-2026-58044 | nodejs: Node.js: Request smuggling via HTTP client header truncation | MEDIUM | 4.8 | Aug 4, 2026 |
| CVE-2026-58045 | nodejs: Node.js: Denial of Service vulnerability | MEDIUM | 6.2 | Aug 4, 2026 |
| CVE-2026-58041 | nodejs: Node.js node:sqlite: Unintended data modification due to stale statement iterator | MEDIUM | 5.3 | Aug 4, 2026 |
| CVE-2026-58039 | nodejs: Information disclosure due to improper permission enforcement | MEDIUM | 4.4 | Jul 31, 2026 |
| CVE-2026-56847 | nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions | MEDIUM | 6.1 | Jul 30, 2026 |
| CVE-2026-58043 | nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw | HIGH | 8.4 | Jul 30, 2026 |
| CVE-2026-56850 | nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw | MEDIUM | 4.4 | Jul 30, 2026 |
| CVE-2026-58040 | nodejs: HTTPS Agent TLS session reuse skips hostname verification | MEDIUM | 6.3 | Jul 30, 2026 |
| CVE-2026-48930 | nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling | CRITICAL | 9.8 | Jun 26, 2026 |
| CVE-2026-48928 | Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency | MEDIUM | 5.4 | Jun 26, 2026 |
| CVE-2026-48934 | nodejs: Node.js: Certification validation bypass in TLS host verification | MEDIUM | 4.3 | Jun 26, 2026 |
| CVE-2026-48936 | nodejs: Node.js: Local server can be started without network permission via Permission API flaw | LOW | 3.3 | Jun 26, 2026 |
| CVE-2026-48618 | nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch | MEDIUM | 6.5 | Jun 26, 2026 |
| CVE-2026-48933 | nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48935 | nodejs: Node.js: Unauthorized file metadata modification | LOW | 3.3 | Jun 26, 2026 |
| CVE-2026-48619 | nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48615 | nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48931 | nodejs: Node.js HTTP Agent: Information disclosure due to premature response acceptance | LOW | 3.7 | Jun 22, 2026 |
| CVE-2026-48937 | nodejs: Node.js HTTP/2 Server: Denial of Service due to continued data acceptance after GOAWAY frame | HIGH | 7.5 | Jun 18, 2026 |
| CVE-2026-48617 | nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation | HIGH | 8.2 | Jun 18, 2026 |
| CVE-2026-21710 | Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header | HIGH | 7.5 | Mar 30, 2026 |
Showing 1 to 25 of 74 CVEs