Node.js / Node.js
187 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-56847 | nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions | MEDIUM | 6.1 | Jul 30, 2026 |
| CVE-2026-58043 | nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw | HIGH | 8.4 | Jul 30, 2026 |
| CVE-2026-56850 | nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw | MEDIUM | 4.4 | Jul 30, 2026 |
| CVE-2026-48930 | nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling | CRITICAL | 9.8 | Jun 26, 2026 |
| CVE-2026-48928 | Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency | MEDIUM | 5.4 | Jun 26, 2026 |
| CVE-2026-48934 | nodejs: Node.js: Certification validation bypass in TLS host verification | MEDIUM | 4.3 | Jun 26, 2026 |
| CVE-2026-48936 | nodejs: Node.js: Local server can be started without network permission via Permission API flaw | LOW | 3.3 | Jun 26, 2026 |
| CVE-2026-48618 | nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch | MEDIUM | 6.5 | Jun 26, 2026 |
| CVE-2026-48933 | nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48935 | nodejs: Node.js: Unauthorized file metadata modification | LOW | 3.3 | Jun 26, 2026 |
| CVE-2026-48619 | nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48615 | nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-48931 | nodejs: Node.js HTTP Agent: Information disclosure due to premature response acceptance | LOW | 3.7 | Jun 22, 2026 |
| CVE-2026-48937 | nodejs: Node.js HTTP/2 Server: Denial of Service due to continued data acceptance after GOAWAY frame | HIGH | 7.5 | Jun 18, 2026 |
| CVE-2026-48617 | nodejs: Node.js: Permission Model bypass via `process.report.writeReport()` path misvalidation | HIGH | 8.2 | Jun 18, 2026 |
| CVE-2026-21710 | Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header | HIGH | 7.5 | Mar 30, 2026 |
| CVE-2026-21716 | nodejs: Node.js: Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix. | LOW | 3.8 | Mar 30, 2026 |
| CVE-2026-21711 | Node.js: Node.js: Unauthorized inter-process communication due to missing Unix Domain Socket permission checks | MEDIUM | 5.2 | Mar 30, 2026 |
| CVE-2026-21715 | Node.js: Node.js: Information disclosure due to `fs.realpathSync.native()` bypassing filesystem read restrictions | LOW | 3.3 | Mar 30, 2026 |
| CVE-2026-21717 | nodejs: v8: Node.js: Denial of Service via V8 string hashing mechanism due to predictable hash collisions | MEDIUM | 5.9 | Mar 30, 2026 |
| CVE-2026-21713 | Node.js: Node.js: Information disclosure via timing oracle in HMAC verification | MEDIUM | 5.9 | Mar 30, 2026 |
| CVE-2026-21714 | Node.js: Node.js: Memory leak and Denial of Service via crafted HTTP/2 WINDOW_UPDATE frames | MEDIUM | 5.3 | Mar 30, 2026 |
| CVE-2026-21712 | Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing | MEDIUM | 6.5 | Mar 30, 2026 |
| CVE-2026-21636 | nodejs: Nodejs network segmentation bypass | CRITICAL | 10.0 | Jan 20, 2026 |
| CVE-2025-59466 | nodejs: Nodejs denial of service | HIGH | 7.5 | Jan 20, 2026 |
Showing 1 to 25 of 187 CVEs