nodejs / node.js
15 known vulnerabilities in nodejs node.js.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-21710 | Medium | 25.0% | 7.5 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a re… | |
| CVE-2026-48933 | Medium | 3.7% | 7.5 | A flaw in Node.js WebCrypto implementation can crash the process if the input of… | |
| CVE-2026-48937 | Medium | 0.6% | 7.5 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data eve… | |
| CVE-2026-48617 | Medium | 0.3% | 8.2 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report… | |
| CVE-2026-58043 | Medium | 0.1% | 8.4 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access … | |
| CVE-2026-48618 | Low | 3.2% | 6.5 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator … | |
| CVE-2026-21714 | Low | 0.5% | 5.3 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE… | |
| CVE-2026-21713 | Low | 0.4% | 5.9 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when val… | |
| CVE-2026-21712 | Low | 0.3% | 6.5 | A flaw in Node.js URL processing causes an assertion failure in native code when… | |
| CVE-2026-21717 | Low | 0.3% | 5.9 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed… | |
| CVE-2026-21711 | Low | 0.2% | 5.3 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket… | |
| CVE-2026-21715 | Low | 0.2% | 3.3 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSyn… | |
| CVE-2026-56847 | Low | 0.2% | 6.1 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracin… | |
| CVE-2026-21716 | Low | 0.1% | 3.3 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle… | |
| CVE-2026-56850 | Low | 0.1% | 4.4 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co… |