CVE-2025-55130
- EPSS 0.01%
- Veröffentlicht 20.01.2026 20:41:55
- Zuletzt bearbeitet 03.02.2026 21:29:50
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory c...
CVE-2025-55132
- EPSS 0%
- Veröffentlicht 20.01.2026 20:41:55
- Zuletzt bearbeitet 03.02.2026 21:27:22
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks,...
CVE-2025-59464
- EPSS 0.04%
- Veröffentlicht 20.01.2026 20:41:55
- Zuletzt bearbeitet 30.01.2026 20:26:26
A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing re...
CVE-2025-59465
- EPSS 0.06%
- Veröffentlicht 20.01.2026 20:41:55
- Zuletzt bearbeitet 30.01.2026 20:25:39
A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of s...
CVE-2025-59466
- EPSS 0.02%
- Veröffentlicht 20.01.2026 20:41:55
- Zuletzt bearbeitet 30.01.2026 20:25:11
We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making th...
- EPSS 0.03%
- Veröffentlicht 20.01.2026 20:41:55
- Zuletzt bearbeitet 30.01.2026 20:20:56
A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath options) can connect to...
CVE-2026-21637
- EPSS 0.03%
- Veröffentlicht 20.01.2026 20:41:55
- Zuletzt bearbeitet 30.01.2026 20:18:32
A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths ...
CVE-2025-23084
- EPSS 0.05%
- Veröffentlicht 28.01.2025 05:15:11
- Zuletzt bearbeitet 04.11.2025 22:16:07
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative ...
CVE-2024-27980
- EPSS 0.19%
- Veröffentlicht 09.01.2025 01:15:08
- Zuletzt bearbeitet 09.01.2025 22:15:27
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
CVE-2023-30582
- EPSS 0.11%
- Veröffentlicht 07.09.2024 16:15:02
- Zuletzt bearbeitet 21.11.2024 08:00:27
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict f...