nodejs

219 tracked vulnerabilities.

CVE-2023-32003 MEDIUM
Node.js 20.0.0-20.4.9 - Path Traversal via fs.mkdtemp()
Aug 15, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-30589 HIGH
Node.js 16.0.0-16.20.1 - HTTP Request Smuggling via CR Delimiter in llhttp Parser
Jul 01, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-30586 HIGH
Node.js 20.0.0-20.3.0 - Privilege Escalation via OpenSSL Engine Loading
Jul 01, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-23920 MEDIUM
Node.js <19.6.1-<14.21.3 - Privilege Escalation
Feb 23, 2023
CVSS 4.2
EPSS 0.00
CVE-2023-23919 HIGH
Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 - DoS
Feb 23, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-23918 HIGH
Node.js <19.6.1, <18.14.1, <16.19.1, <14.21.3 - Privilege Escalation
Feb 23, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-24807 HIGH
Undici < 5.19.1 - Regular Expression Denial of Service via Header Value Normalization
Feb 16, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-23936 MEDIUM
Undici <5.19.1 - CRLF Injection
Feb 16, 2023
CVSS 6.5
EPSS 0.00
CVE-2022-43548 HIGH
Node.js <14.21.1, <16.18.1, <18.12.1, <19.0.1 - Command Injection
Dec 05, 2022
CVSS 8.1
EPSS 0.01
CVE-2022-35256 MEDIUM
Node.js 14.0.0-14.13.1, 14.15.0-14.20.0 and llhttp < 6.0.10 - HTTP Request Smuggling via Header Field Parsing
Dec 05, 2022
CVSS 6.5
EPSS 0.04
CVE-2022-35255 CRITICAL
Node.js 15.0.0-15.13.0 and 16.13.0-16.17.0 - Weak Cryptographic Key Generation via WebCrypto EntropySource
Dec 05, 2022
CVSS 9.1
EPSS 0.01
CVE-2022-3786 HIGH
OpenSSL 3.0.0-3.0.7 - Buffer Overflow in X.509 Certificate Name Constraint Checking
Nov 01, 2022
CVSS 7.5
EPSS 0.27
CVE-2022-3602 HIGH
OpenSSL 3.0.0-3.0.6 - Buffer Overflow in X.509 Certificate Name Constraint Checking
Nov 01, 2022
CVSS 7.5
EPSS 0.84
CVE-2022-35948 MEDIUM
undici < 5.8.1 - CRLF Injection via Content-Type Header
Aug 15, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-35949 MEDIUM
undici <5.8.2 - Server-Side Request Forgery via pathname URL Confusion
Aug 12, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-31151 LOW
undici < 5.7.1 - Cookie Header Leakage on Cross-Origin Redirect
Jul 21, 2022
CVSS 3.7
EPSS 0.00
CVE-2022-31150 MEDIUM
undici < 5.8.0 - CRLF Injection in HTTP Headers
Jul 19, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-32223 HIGH
Node.js 14.0.0-14.13.1 and 14.14.0-14.19.3 - DLL Hijacking via OpenSSL Configuration Path
Jul 14, 2022
CVSS 7.3
EPSS 0.08
CVE-2022-32222 MEDIUM
Node.js 18.x < 18.40.0 - Cryptographic Configuration Path Vulnerability
Jul 14, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-32215 MEDIUM
llhttp <14.20.1, <16.17.1, <18.9.1 - HTTP Request Smuggling via Multi-line Transfer-Encoding Header
Jul 14, 2022
CVSS 6.5
EPSS 0.86
CVE-2022-32214 MEDIUM
llhttp < 2.1.5 - HTTP Request Smuggling via CRLF Sequence Mismanagement
Jul 14, 2022
CVSS 6.5
EPSS 0.39
CVE-2022-32213 MEDIUM
llhttp < 2.1.5 - HTTP Request Smuggling via Transfer-Encoding Header
Jul 14, 2022
CVSS 6.5
EPSS 0.86
CVE-2022-32212 HIGH
Node.js <14.20.0, <16.20.0, <18.5.0 - OS Command Injection via IsAllowedHost Bypass
Jul 14, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-32210 MEDIUM
Undici 4.8.2-5.5.0 - Improper Certificate Validation in ProxyAgent
Jul 14, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-0778 HIGH
OpenSSL 1.0.2-1.0.2zc, 1.1.1-1.1.1m, 3.0.0-3.0.1 - Denial of Service via BN_mod_sqrt Infinite Loop
Mar 15, 2022
CVSS 7.5
EPSS 0.07