← All vendors

nodejs

37 known vulnerabilities affecting nodejs products.

Products

undici 22 node.js 15

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-21710 Medium 25.0% 7.5 A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a re…
CVE-2026-48933 Medium 3.7% 7.5 A flaw in Node.js WebCrypto implementation can crash the process if the input of…
CVE-2026-1526 Medium 1.2% 7.5 The undici WebSocket client is vulnerable to a denial-of-service attack via unbo…
CVE-2026-2229 Medium 0.9% 7.5 ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack du…
CVE-2026-12151 Medium 0.8% 7.5 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative by…
CVE-2026-48937 Medium 0.6% 7.5 A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data eve…
CVE-2026-1528 Medium 0.5% 7.5 ImpactA server can reply with a WebSocket frame using the 64-bit length form and…
CVE-2026-13697 Medium 0.5% 7.4 undici's cache interceptor mishandles malformed Cache-Control private directives…
CVE-2026-9697 Medium 0.5% 7.4 Impact: undici's ProxyAgent silently drops the requestTls option when configured…
CVE-2026-19534 Medium 0.4% 7.5 undici's WebSocket client crashes the whole Node.js process during the opening h…
CVE-2026-6734 Medium 0.3% 7.5 Impact: When using Socks5ProxyAgent, undici reuses a single connection pool acro…
CVE-2026-48617 Medium 0.3% 8.2 A flaw in Node.js Permission Model enforcement allows Bypass via `process.report…
CVE-2026-85152 Medium 0.2% 7.4 undici 8.10.0 omits the destination origin from the cache and request-deduplicat…
CVE-2026-58043 Medium 0.1% 8.4 A flaw in Node.js Permission Model enforcement can over-grant filesystem access …
CVE-2026-84961 Medium 0.1% 7.4 undici's BalancedPool constructor passes its entire options object through an in…
CVE-2026-48618 Low 3.2% 6.5 A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator …
CVE-2026-21714 Low 0.5% 5.3 A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE…
CVE-2026-21713 Low 0.4% 5.9 A flaw in Node.js HMAC verification uses a non-constant-time comparison when val…
CVE-2026-85014 Low 0.4% 5.9 undici's experimental WebSocketStream client crashes the whole Node.js process w…
CVE-2026-18149 Low 0.4% 5.9 undici's retry handler can leave an already-exposed response body pending foreve…
CVE-2026-21712 Low 0.3% 6.5 A flaw in Node.js URL processing causes an assertion failure in native code when…
CVE-2026-14643 Low 0.3% 5.9 undici's cache interceptor mishandles optional whitespace placed around the equa…
CVE-2026-21717 Low 0.3% 5.9 A flaw in V8's string hashing mechanism causes integer-like strings to be hashed…
CVE-2026-85024 Low 0.3% 5.9 undici bundles a WebSocket client whose permessage-deflate size-limit cleanup re…
CVE-2026-84890 Low 0.3% 5.9 undici's decompress interceptor decompresses response bodies according to the un…
CVE-2026-84933 Low 0.2% 6.5 undici's cache interceptor does not handle the Set-Cookie response header anywhe…
CVE-2026-18540 Low 0.2% 3.7 undici's retry interceptor can append the body of a ranged retry response to byt…
CVE-2026-84947 Low 0.2% 3.7 undici's dump interceptor reads and discards a response body up to a configurabl…
CVE-2026-15157 Low 0.2% 4.2 undici does not validate the type property of a duck-typed blob-like request bod…
CVE-2026-16729 Low 0.2% 4.8 undici's setCookie function does not fully sanitize cookie attributes. In undici…
CVE-2026-16728 Low 0.2% 4.8 undici's retry interceptor can deliver a response whose body length does not mat…
CVE-2026-21711 Low 0.2% 5.3 A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket…
CVE-2026-21715 Low 0.2% 3.3 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSyn…
CVE-2026-56847 Low 0.2% 6.1 A flaw in Node.js Permission Model enforcement allows `trace_events.createTracin…
CVE-2026-21716 Low 0.1% 3.3 An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle…
CVE-2026-85008 Low 0.1% 3.7 undici's cache interceptor documents that only safe HTTP methods are cached, but…
CVE-2026-56850 Low 0.1% 4.4 A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key co…