Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Node.js

Node.jsпрограммная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)

Релизный цикл, информация об уязвимостях

Продукт: Node.js
Вендор: nodejs

График релизов

22232425262024202520262027202820292030

Релизные элементы

KBВерсияБилдДата доступности
24.21.024.21.0
24.20.024.20.0
24.19.024.19.0
24.18.124.18.1
24.18.024.18.0
24.17.024.17.0
24.16.024.16.0
24.15.024.15.0
24.14.124.14.1
24.14.024.14.0

Показывать по

Недавние уязвимости Node.js

Количество 1 270

debian логотип

CVE-2026-48933

3 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if th ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-48933

3 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-48930

3 месяца назад

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnam ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-48930

3 месяца назад

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-48928

3 месяца назад

A inconsistency in Node.js hostname matching can cause a trust-policy ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-48928

3 месяца назад

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-48619

3 месяца назад

A flaw in Node.js HTTP/2 client allows a server to send an unlimited n ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-48619

3 месяца назад

A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-48618

3 месяца назад

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-48618

3 месяца назад

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if th ...

CVSS3: 7.5
4%
Низкий
3 месяца назад
nvd логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
4%
Низкий
3 месяца назад
debian логотип
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnam ...

CVSS3: 9.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 9.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-48928

A inconsistency in Node.js hostname matching can cause a trust-policy ...

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-48928

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 5.4
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-48619

A flaw in Node.js HTTP/2 client allows a server to send an unlimited n ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-48619

A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-48618

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot ...

CVSS3: 6.5
3%
Низкий
3 месяца назад
nvd логотип
CVE-2026-48618

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 6.5
3%
Низкий
3 месяца назад

Уязвимостей на страницу


Поделиться