nodejs
219 tracked vulnerabilities.
CVE-2023-32003
MEDIUM
Node.js 20.0.0-20.4.9 - Path Traversal via fs.mkdtemp()
Aug 15, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-30589
HIGH
Node.js 16.0.0-16.20.1 - HTTP Request Smuggling via CR Delimiter in llhttp Parser
Jul 01, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-30586
HIGH
Node.js 20.0.0-20.3.0 - Privilege Escalation via OpenSSL Engine Loading
Jul 01, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-23920
MEDIUM
Node.js <19.6.1-<14.21.3 - Privilege Escalation
Feb 23, 2023
CVSS 4.2
EPSS 0.00
CVE-2023-23919
HIGH
Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 - DoS
Feb 23, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-23918
HIGH
Node.js <19.6.1, <18.14.1, <16.19.1, <14.21.3 - Privilege Escalation
Feb 23, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-24807
HIGH
Undici < 5.19.1 - Regular Expression Denial of Service via Header Value Normalization
Feb 16, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-23936
MEDIUM
Undici <5.19.1 - CRLF Injection
Feb 16, 2023
CVSS 6.5
EPSS 0.00
CVE-2022-43548
HIGH
Node.js <14.21.1, <16.18.1, <18.12.1, <19.0.1 - Command Injection
Dec 05, 2022
CVSS 8.1
EPSS 0.01
CVE-2022-35256
MEDIUM
Node.js 14.0.0-14.13.1, 14.15.0-14.20.0 and llhttp < 6.0.10 - HTTP Request Smuggling via Header Field Parsing
Dec 05, 2022
CVSS 6.5
EPSS 0.04
CVE-2022-35255
CRITICAL
Node.js 15.0.0-15.13.0 and 16.13.0-16.17.0 - Weak Cryptographic Key Generation via WebCrypto EntropySource
Dec 05, 2022
CVSS 9.1
EPSS 0.01
CVE-2022-3786
HIGH
OpenSSL 3.0.0-3.0.7 - Buffer Overflow in X.509 Certificate Name Constraint Checking
Nov 01, 2022
CVSS 7.5
EPSS 0.27
CVE-2022-3602
HIGH
OpenSSL 3.0.0-3.0.6 - Buffer Overflow in X.509 Certificate Name Constraint Checking
Nov 01, 2022
CVSS 7.5
EPSS 0.84
CVE-2022-35948
MEDIUM
undici < 5.8.1 - CRLF Injection via Content-Type Header
Aug 15, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-35949
MEDIUM
undici <5.8.2 - Server-Side Request Forgery via pathname URL Confusion
Aug 12, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-31151
LOW
undici < 5.7.1 - Cookie Header Leakage on Cross-Origin Redirect
Jul 21, 2022
CVSS 3.7
EPSS 0.00
CVE-2022-31150
MEDIUM
undici < 5.8.0 - CRLF Injection in HTTP Headers
Jul 19, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-32223
HIGH
Node.js 14.0.0-14.13.1 and 14.14.0-14.19.3 - DLL Hijacking via OpenSSL Configuration Path
Jul 14, 2022
CVSS 7.3
EPSS 0.08
CVE-2022-32222
MEDIUM
Node.js 18.x < 18.40.0 - Cryptographic Configuration Path Vulnerability
Jul 14, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-32215
MEDIUM
llhttp <14.20.1, <16.17.1, <18.9.1 - HTTP Request Smuggling via Multi-line Transfer-Encoding Header
Jul 14, 2022
CVSS 6.5
EPSS 0.86
CVE-2022-32214
MEDIUM
llhttp < 2.1.5 - HTTP Request Smuggling via CRLF Sequence Mismanagement
Jul 14, 2022
CVSS 6.5
EPSS 0.39
CVE-2022-32213
MEDIUM
llhttp < 2.1.5 - HTTP Request Smuggling via Transfer-Encoding Header
Jul 14, 2022
CVSS 6.5
EPSS 0.86
CVE-2022-32212
HIGH
Node.js <14.20.0, <16.20.0, <18.5.0 - OS Command Injection via IsAllowedHost Bypass
Jul 14, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-32210
MEDIUM
Undici 4.8.2-5.5.0 - Improper Certificate Validation in ProxyAgent
Jul 14, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-0778
HIGH
OpenSSL 1.0.2-1.0.2zc, 1.1.1-1.1.1m, 3.0.0-3.0.1 - Denial of Service via BN_mod_sqrt Infinite Loop
Mar 15, 2022
CVSS 7.5
EPSS 0.07
Products
Quick Filters