nodejs
37 known vulnerabilities affecting nodejs products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-21710 | Medium | 25.0% | 7.5 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a re… | |
| CVE-2026-48933 | Medium | 3.7% | 7.5 | A flaw in Node.js WebCrypto implementation can crash the process if the input of… | |
| CVE-2026-1526 | Medium | 1.2% | 7.5 | The undici WebSocket client is vulnerable to a denial-of-service attack via unbo… | |
| CVE-2026-2229 | Medium | 0.9% | 7.5 | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack du… | |
| CVE-2026-12151 | Medium | 0.8% | 7.5 | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative by… | |
| CVE-2026-48937 | Medium | 0.6% | 7.5 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data eve… | |
| CVE-2026-1528 | Medium | 0.5% | 7.5 | ImpactA server can reply with a WebSocket frame using the 64-bit length form and… | |
| CVE-2026-13697 | Medium | 0.5% | 7.4 | undici's cache interceptor mishandles malformed Cache-Control private directives… | |
| CVE-2026-9697 | Medium | 0.5% | 7.4 | Impact: undici's ProxyAgent silently drops the requestTls option when configured… | |
| CVE-2026-19534 | Medium | 0.4% | 7.5 | undici's WebSocket client crashes the whole Node.js process during the opening h… | |
| CVE-2026-6734 | Medium | 0.3% | 7.5 | Impact: When using Socks5ProxyAgent, undici reuses a single connection pool acro… | |
| CVE-2026-48617 | Medium | 0.3% | 8.2 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report… | |
| CVE-2026-85152 | Medium | 0.2% | 7.4 | undici 8.10.0 omits the destination origin from the cache and request-deduplicat… | |
| CVE-2026-58043 | Medium | 0.1% | 8.4 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access … | |
| CVE-2026-84961 | Medium | 0.1% | 7.4 | undici's BalancedPool constructor passes its entire options object through an in… | |
| CVE-2026-48618 | Low | 3.2% | 6.5 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator … | |
| CVE-2026-21714 | Low | 0.5% | 5.3 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE… | |
| CVE-2026-21713 | Low | 0.4% | 5.9 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when val… | |
| CVE-2026-85014 | Low | 0.4% | 5.9 | undici's experimental WebSocketStream client crashes the whole Node.js process w… | |
| CVE-2026-18149 | Low | 0.4% | 5.9 | undici's retry handler can leave an already-exposed response body pending foreve… | |
| CVE-2026-21712 | Low | 0.3% | 6.5 | A flaw in Node.js URL processing causes an assertion failure in native code when… | |
| CVE-2026-14643 | Low | 0.3% | 5.9 | undici's cache interceptor mishandles optional whitespace placed around the equa… | |
| CVE-2026-21717 | Low | 0.3% | 5.9 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed… | |
| CVE-2026-85024 | Low | 0.3% | 5.9 | undici bundles a WebSocket client whose permessage-deflate size-limit cleanup re… | |
| CVE-2026-84890 | Low | 0.3% | 5.9 | undici's decompress interceptor decompresses response bodies according to the un… | |
| CVE-2026-84933 | Low | 0.2% | 6.5 | undici's cache interceptor does not handle the Set-Cookie response header anywhe… | |
| CVE-2026-18540 | Low | 0.2% | 3.7 | undici's retry interceptor can append the body of a ranged retry response to byt… | |
| CVE-2026-84947 | Low | 0.2% | 3.7 | undici's dump interceptor reads and discards a response body up to a configurabl… | |
| CVE-2026-15157 | Low | 0.2% | 4.2 | undici does not validate the type property of a duck-typed blob-like request bod… | |
| CVE-2026-16729 | Low | 0.2% | 4.8 | undici's setCookie function does not fully sanitize cookie attributes. In undici… | |
| CVE-2026-16728 | Low | 0.2% | 4.8 | undici's retry interceptor can deliver a response whose body length does not mat… | |
| CVE-2026-21711 | Low | 0.2% | 5.3 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket… | |
| CVE-2026-21715 | Low | 0.2% | 3.3 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSyn… | |
| CVE-2026-56847 | Low | 0.2% | 6.1 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracin… | |
| CVE-2026-21716 | Low | 0.1% | 3.3 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle… | |
| CVE-2026-85008 | Low | 0.1% | 3.7 | undici's cache interceptor documents that only safe HTTP methods are cached, but… | |
| CVE-2026-56850 | Low | 0.1% | 4.4 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co… |