Nodejs

Node.Js

197 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 30.03.2026 19:07:28
  • Zuletzt bearbeitet 19.08.2026 13:18:02

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As ...

  • EPSS 0.27%
  • Veröffentlicht 30.03.2026 19:07:28
  • Zuletzt bearbeitet 19.08.2026 12:54:11

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker c...

  • EPSS 0.32%
  • Veröffentlicht 30.03.2026 15:13:59
  • Zuletzt bearbeitet 19.08.2026 14:05:23

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

  • EPSS 1.66%
  • Veröffentlicht 20.01.2026 20:41:55
  • Zuletzt bearbeitet 15.07.2026 02:17:27

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory c...

  • EPSS 0.24%
  • Veröffentlicht 20.01.2026 20:41:55
  • Zuletzt bearbeitet 03.02.2026 21:27:22

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks,...

  • EPSS 0.24%
  • Veröffentlicht 20.01.2026 20:41:55
  • Zuletzt bearbeitet 30.01.2026 20:26:26

A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing re...

  • EPSS 3.76%
  • Veröffentlicht 20.01.2026 20:41:55
  • Zuletzt bearbeitet 15.07.2026 02:17:30

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of s...

  • EPSS 0.65%
  • Veröffentlicht 20.01.2026 20:41:55
  • Zuletzt bearbeitet 30.01.2026 20:25:11

We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making th...

  • EPSS 0.69%
  • Veröffentlicht 20.01.2026 20:41:55
  • Zuletzt bearbeitet 30.01.2026 20:20:56

A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath options) can connect to...

Medienbericht
  • EPSS 1.1%
  • Veröffentlicht 20.01.2026 20:41:55
  • Zuletzt bearbeitet 30.01.2026 20:18:32

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths ...