Nodejs Security Vulnerabilities (CVEs)
Track 32 security vulnerabilities affecting Nodejs products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
A critical vulnerability in Node.js v25's experimental permission model allows attacker-controlled inputs to bypass network restrictions and connect t...
Jan 20, 2026A Node.js TLS vulnerability allows remote attackers to crash TLS servers or cause resource exhaustion by triggering unhandled exceptions in PSK or ALP...
Jan 20, 2026A malformed HTTP/2 HEADERS frame with oversized, invalid HPACK data can cause Node.js to crash due to an unhandled TLSSocket ECONNRESET error, enablin...
Jan 20, 2026This vulnerability in Node.js causes applications to crash unrecoverably when deep recursion triggers 'Maximum call stack size exceeded' errors while ...
Jan 20, 2026A Node.js permissions model vulnerability allows attackers to bypass file system access restrictions using crafted relative symlink paths. This enable...
Jan 20, 2026A vulnerability in Node.js's permission model allows attackers to modify file timestamps using the futimes() function even when they only have read pe...
Jan 20, 2026A memory leak vulnerability in Node.js's OpenSSL integration allows remote attackers to cause denial of service through resource exhaustion. When appl...
Jan 20, 2026This vulnerability in Undici HTTP client allows a malicious server to send specially crafted compressed responses that force the client to perform exc...
Jan 14, 2026This Node.js vulnerability on Windows incorrectly handles drive names in path.join(), treating relative paths as root directory references. This allow...
Jan 28, 2025CVE-2024-3566 is a command injection vulnerability affecting Windows applications that use CreateProcess function with improper argument quoting. Atta...
Apr 10, 2024This vulnerability allows attackers to bypass Node.js's experimental permission model by overwriting built-in path normalization functions, enabling p...
Feb 20, 2024This CVE describes a path traversal vulnerability in Node.js's experimental permission model where attackers can bypass path validation by monkey-patc...
Feb 20, 2024This vulnerability in Node.js's crypto module causes the generateKeys() function to not properly generate public keys after setPrivateKey() is called,...
Nov 28, 2023This vulnerability allows unprivileged Windows users to manipulate the %USERPROFILE% registry variable during Node.js MSI installer repair operations,...
Nov 28, 2023This vulnerability allows attackers to bypass Node.js's experimental policy mechanism by using __proto__ to require modules outside the policy.json de...
Nov 23, 2023CVE-2023-38552 is a security bypass vulnerability in Node.js's experimental policy mechanism that allows attackers to forge checksums and disable inte...
Oct 18, 2023This vulnerability allows path traversal attacks in Node.js when using non-Buffer Uint8Array objects with fs module functions. Attackers can potential...
Oct 18, 2023CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server res...
Oct 10, 2023CVE-2023-32558 allows attackers to bypass Node.js's experimental permission model using the deprecated process.binding() API, enabling path traversal ...
Sep 12, 2023This CVE describes a path traversal vulnerability in Node.js 20's experimental permission model where improper Buffer handling in file system APIs all...
Aug 15, 2023This vulnerability in Node.js's llhttp parser allows HTTP Request Smuggling (HRS) by accepting carriage return (CR) characters alone instead of requir...
Jul 1, 2023A cryptographic vulnerability in Node.js versions before specified patches fails to clear OpenSSL error stacks after operations, potentially causing f...
Feb 23, 2023This CVE describes an OS command injection vulnerability in Node.js that allows attackers to bypass host validation checks and perform DNS rebinding a...
Jul 14, 2022Node.js on Windows is vulnerable to DLL hijacking when OpenSSL is installed with a specific configuration file path. This allows attackers to execute ...
Jul 14, 2022CVE-2022-0778 is a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function that can cause infinite loops when parsing specially crafted ce...
Mar 15, 2022This CVE describes a prototype pollution vulnerability in Node.js's console.table() function when user-controlled input is passed to the 'properties' ...
Feb 24, 2022This vulnerability in Node.js allows attackers to bypass certificate name constraints by using arbitrary Subject Alternative Name (SAN) types, particu...
Feb 24, 2022CVE-2021-22930 is a use-after-free vulnerability in Node.js that allows memory corruption attacks. An attacker could exploit this to execute arbitrary...
Oct 7, 2021Node.js DNS library vulnerability allows remote code execution, XSS, and application crashes due to improper validation of DNS responses. Attackers ca...
Aug 16, 2021CVE-2021-22940 is a use-after-free vulnerability in Node.js that allows memory corruption attacks. An attacker could exploit this to potentially execu...
Aug 16, 2021This vulnerability allows local attackers on Windows systems to escalate privileges through PATH and DLL hijacking attacks. It affects Node.js install...
Jul 12, 2021Node.js servers are vulnerable to denial of service attacks when attackers establish numerous connections with unknown protocols, causing file descrip...
Mar 3, 2021Why Monitor Nodejs Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 32+ known vulnerabilities affecting Nodejs products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Nodejs packages in under 60 seconds. No agents required - completely agentless scanning that works across Nodejs deployments.
Free vulnerability database: Access detailed information about every Nodejs CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Nodejs CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions