Количество 1 270
Количество 1 270
openSUSE-SU-2019:1211-1
Security update for nodejs10
openSUSE-SU-2018:1962-1
Security update for nodejs6
openSUSE-SU-2015:1825-2
Security update for nodejs
openSUSE-SU-2015:1825-1
Security update for nodejs
SUSE-SU-2023:0682-1
Security update for nodejs12
SUSE-SU-2023:0606-1
Security update for nodejs10
SUSE-SU-2022:4301-1
Security update for nodejs10
SUSE-SU-2022:4255-1
Security update for nodejs14
SUSE-SU-2022:4254-1
Security update for nodejs12
SUSE-SU-2022:4084-1
Security update for nodejs16
SUSE-SU-2022:4003-1
Security update for nodejs16
SUSE-SU-2022:3989-1
Security update for nodejs12
SUSE-SU-2022:3968-1
Security update for nodejs14
SUSE-SU-2022:3967-1
Security update for nodejs16
SUSE-SU-2019:0636-1
Security update for nodejs10
SUSE-SU-2019:0635-1
Security update for nodejs8
SUSE-SU-2019:0627-1
Security update for nodejs10
SUSE-SU-2018:1892-1
Security update for nodejs6
GHSA-xv6w-gxj8-v943
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
GHSA-x6fg-f45m-jf5q
Regular Expression Denial of Service in semver
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2019:1211-1 Security update for nodejs10 | 16% Средний | больше 7 лет назад | ||
openSUSE-SU-2018:1962-1 Security update for nodejs6 | 7% Низкий | около 8 лет назад | ||
openSUSE-SU-2015:1825-2 Security update for nodejs | 8% Низкий | почти 11 лет назад | ||
openSUSE-SU-2015:1825-1 Security update for nodejs | 8% Низкий | почти 11 лет назад | ||
SUSE-SU-2023:0682-1 Security update for nodejs12 | 0% Низкий | больше 3 лет назад | ||
SUSE-SU-2023:0606-1 Security update for nodejs10 | 0% Низкий | больше 3 лет назад | ||
SUSE-SU-2022:4301-1 Security update for nodejs10 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2022:4255-1 Security update for nodejs14 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2022:4254-1 Security update for nodejs12 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2022:4084-1 Security update for nodejs16 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2022:4003-1 Security update for nodejs16 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2022:3989-1 Security update for nodejs12 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2022:3968-1 Security update for nodejs14 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2022:3967-1 Security update for nodejs16 | 14% Средний | почти 4 года назад | ||
SUSE-SU-2019:0636-1 Security update for nodejs10 | 16% Средний | больше 7 лет назад | ||
SUSE-SU-2019:0635-1 Security update for nodejs8 | 16% Средний | больше 7 лет назад | ||
SUSE-SU-2019:0627-1 Security update for nodejs10 | 16% Средний | больше 7 лет назад | ||
SUSE-SU-2018:1892-1 Security update for nodejs6 | 7% Низкий | около 8 лет назад | ||
GHSA-xv6w-gxj8-v943 A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x** | CVSS3: 7.5 | 25% Средний | 6 месяцев назад | |
GHSA-x6fg-f45m-jf5q Regular Expression Denial of Service in semver | CVSS3: 7.5 | 6% Низкий | почти 9 лет назад |
Уязвимостей на страницу