LIVE · cybersecurity feed
Live wire
vendor

Nodejs

18 CVEs published in the last four months. Exploited flaws first.

Critical1
High14
Medium3
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-489309.8criticalnode.jsA flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding du71d ago
CVE-2026-580438.4highnode.jsA flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundarie37d ago
CVE-2026-486178.2highnode.jsA flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation79d ago
CVE-2026-486197.5highnode.jsA flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to 71d ago
CVE-2026-121517.5highundiciImpact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message80d ago
CVE-2026-15267.5highundiciThe undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during per177d ago
CVE-2026-22297.5highundiciImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the ser177d ago
CVE-2026-15287.5highundiciImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length.177d ago
CVE-2026-96757.5highundiciImpact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of f80d ago
CVE-2026-67347.5highundiciImpact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verify80d ago
CVE-2026-489377.5highnode.jsA flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame.79d ago
CVE-2026-486157.5highnode.jsA flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.71d ago
CVE-2026-489337.5highnode.jsA flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple 71d ago
CVE-2026-96977.4highundiciImpact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5://80d ago
CVE-2026-136977.4highundiciundici's cache interceptor mishandles malformed Cache-Control private directives.38d ago
CVE-2026-15256.5mediumundiciUndici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g177d ago
CVE-2026-25815.9mediumundiciThis is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).177d ago
CVE-2026-15274.6mediumundiciImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can i177d ago

Filter the full tracker by Nodejs