VYPR

Vendor CVEs

Node.js

All CVEs

279 total · sorted by risk
  • CVE-2026-48935LowJun 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2024-36137LowSep 7, 2024
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only"…

  • CVE-2026-15157MedJul 29, 2026
    risk 0.20cvss 4.2epss 0.00

    undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a…

  • CVE-2017-15897LowDec 11, 2017
    risk 0.20cvss 3.1epss 0.02

    Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such…

  • CVE-2024-28607LowMar 11, 2025
    risk 0.19cvss 2.9epss 0.00

    The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.

  • CVE-2024-22018LowJul 10, 2024
    risk 0.19cvss 2.9epss 0.00

    A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious…

  • CVE-2024-30260LowApr 4, 2024
    risk 0.18cvss 3.9epss 0.01

    Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

  • CVE-2024-24758LowFeb 16, 2024
    risk 0.18cvss 3.9epss 0.01

    Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There…

  • CVE-2023-45143LowOct 12, 2023
    risk 0.18cvss 3.9epss 0.01

    Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Cookie` headers. By design, `cookie` headers are forbidden request headers, disallowing them to be…

  • CVE-2026-18540LowSep 4, 2026
    risk 0.17cvss 3.7epss 0.00

    undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a…

  • CVE-2026-85008LowSep 4, 2026
    risk 0.17cvss 3.7epss 0.00

    undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead…

  • CVE-2026-84947LowSep 4, 2026
    risk 0.17cvss 3.7epss 0.00

    undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead…

  • CVE-2026-6733LowJun 17, 2026
    risk 0.17cvss 3.7epss 0.00

    Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request…

  • CVE-2026-11525LowJun 17, 2026
    risk 0.17cvss 3.7epss 0.00

    Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens.…

  • CVE-2022-31151LowJul 21, 2022
    risk 0.17cvss 3.7epss 0.01

    Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users using cookie headers in undici. This may lead to accidental leakage of cookie to a…

  • CVE-2026-21715LowMar 30, 2026
    risk 0.14cvss 3.3epss 0.00

    A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted…

  • CVE-2025-47279LowMay 15, 2025
    risk 0.13cvss 3.1epss 0.00

    Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the…

  • CVE-2024-30261LowApr 4, 2024
    risk 0.10cvss 2.6epss 0.01

    Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

  • CVE-2024-38372LowJul 8, 2024
    risk 0.06cvss 2.0epss 0.00

    Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process. This has been patched in v6.19.2.

  • CVE-2020-11080LowJun 3, 2020
    risk 0.00cvss 3.7epss 0.05

    In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again.…

  • CVE-2020-10531HigMar 12, 2020
    risk 0.00cvss 8.8epss 0.03

    An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

  • CVE-2015-5380Jul 9, 2015
    risk 0.00cvss —epss 0.03

    The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote…

  • CVE-2015-0278May 18, 2015
    risk 0.00cvss —epss 0.03

    libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

  • CVE-2014-7191Oct 19, 2014
    risk 0.00cvss —epss 0.08

    The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

  • CVE-2014-5256Sep 5, 2014
    risk 0.00cvss —epss 0.03

    Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a denial of service (memory corruption and application…

  • CVE-2013-6668Mar 5, 2014
    risk 0.00cvss —epss 0.05

    Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • CVE-2013-4450Oct 21, 2013
    risk 0.00cvss —epss 0.37

    The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.

  • CVE-2013-2882Jul 31, 2013
    risk 0.00cvss —epss 0.03

    Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

  • CVE-2012-2330Aug 13, 2012
    risk 0.00cvss —epss 0.03

    The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length…

Page 6 of 6