Nodejs

Node.Js

167 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.58%
  • Published 05.12.2022 22:15:10
  • Last modified 24.04.2025 14:15:32

The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.

  • EPSS 0.64%
  • Published 05.12.2022 22:15:10
  • Last modified 24.04.2025 14:15:38

A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid befor...

  • EPSS 17.01%
  • Published 01.11.2022 18:15:11
  • Last modified 05.05.2025 16:15:20

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for...

  • EPSS 85.38%
  • Published 01.11.2022 18:15:10
  • Last modified 05.05.2025 16:15:19

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or f...

  • EPSS 0.08%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:56

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making D...

Exploit
  • EPSS 89.07%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:56

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

Exploit
  • EPSS 62%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:56

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

Exploit
  • EPSS 88.11%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:56

The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

Exploit
  • EPSS 0.42%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:57

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in ve...

  • EPSS 9.06%
  • Published 14.07.2022 15:15:08
  • Last modified 21.11.2024 07:05:57

Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Pro...