Nodejs

Node.Js

197 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 26.06.2026 01:14:36
  • Zuletzt bearbeitet 26.06.2026 20:14:33

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2...

  • EPSS 0.15%
  • Veröffentlicht 26.06.2026 01:14:36
  • Zuletzt bearbeitet 26.06.2026 19:55:59

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 22.06.2026 18:59:30
  • Zuletzt bearbeitet 03.07.2026 01:16:22

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • EPSS 0.57%
  • Veröffentlicht 18.06.2026 18:01:39
  • Zuletzt bearbeitet 18.08.2026 17:54:16

A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.

  • EPSS 0.32%
  • Veröffentlicht 18.06.2026 16:21:12
  • Zuletzt bearbeitet 19.08.2026 20:02:10

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability ...

Medienbericht
  • EPSS 25.04%
  • Veröffentlicht 30.03.2026 19:07:28
  • Zuletzt bearbeitet 19.08.2026 14:32:04

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototy...

  • EPSS 0.15%
  • Veröffentlicht 30.03.2026 19:07:28
  • Zuletzt bearbeitet 19.08.2026 13:52:49

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permissi...

  • EPSS 0.39%
  • Veröffentlicht 30.03.2026 19:07:28
  • Zuletzt bearbeitet 19.08.2026 13:36:43

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution t...

  • EPSS 0.45%
  • Veröffentlicht 30.03.2026 19:07:28
  • Zuletzt bearbeitet 19.08.2026 13:35:56

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Se...

  • EPSS 0.16%
  • Veröffentlicht 30.03.2026 19:07:28
  • Zuletzt bearbeitet 19.08.2026 13:32:49

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permissio...