Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

22232425262024202520262027202820292030

Релизные элементы

KBВерсияБилдДата доступности
24.18.124.18.1
24.18.024.18.0
24.17.024.17.0
24.16.024.16.0
24.15.024.15.0
24.14.124.14.1
24.14.024.14.0
24.13.124.13.1
24.13.024.13.0
24.12.024.12.0

Показывать по

Недавние уязвимости Node.js

Количество 1 146

nvd логотип

CVE-2026-48936

около 1 месяца назад

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-48935

около 1 месяца назад

A flaw in Node.js Permission API can cause a file metadata to be modif ...

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-48935

около 1 месяца назад

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-48934

около 1 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypas ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-48934

около 1 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-48933

около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if th ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-48933

около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-48930

около 1 месяца назад

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnam ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-48930

около 1 месяца назад

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-48928

около 1 месяца назад

A inconsistency in Node.js hostname matching can cause a trust-policy ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2026-48936

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modif ...

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48934

A flaw in Node.js TLS host verification can cause an attacker to bypas ...

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48934

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if th ...

CVSS3: 7.5
3%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
3%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnam ...

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48928

A inconsistency in Node.js hostname matching can cause a trust-policy ...

CVSS3: 5.4
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу


Поделиться