Nodejs
Nodejs Node.js: vulnerabilidades y CVE
Nodejs Node.js tiene 204 vulnerabilidades publicadas, 38 de ellas en los últimos 12 meses. 18 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE204
Últimos 12 meses38
Críticas18
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87776 | Alta (7.5) | 0.61% | — | 11 sept 2026 | compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that… |
| CVE-2026-58045 | Media (6.2) | 0.17% | — | 4 ago 2026 | A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.… |
| CVE-2026-58044 | Baja (3.7) | 0.27% | — | 4 ago 2026 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a… |
| CVE-2026-58041 | Media (5.3) | 0.29% | — | 4 ago 2026 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters.… |
| CVE-2026-58039 | Baja (3.3) | 0.15% | — | 31 jul 2026 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary… |
| CVE-2026-67550 | Media (5.7) | 0.16% | — | 30 jul 2026 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test,… |
| CVE-2026-58043 | Alta (8.4) | 0.15% | — | 30 jul 2026 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to… |
| CVE-2026-58040 | Media (6.3) | 0.30% | — | 30 jul 2026 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**,… |
| CVE-2026-56850 | Media (4.4) | 0.08% | — | 30 jul 2026 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This… |
| CVE-2026-56847 | Media (6.1) | 0.16% | — | 30 jul 2026 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security… |
| CVE-2026-48936 | Baja (3.3) | 0.14% | — | 26 jun 2026 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**. |
| CVE-2026-48935 | Baja (3.3) | 0.18% | — | 26 jun 2026 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**,… |
| CVE-2026-48934 | Media (4.3) | 0.26% | — | 26 jun 2026 | A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. |
| CVE-2026-48933 | Alta (7.5) | 3.7% | — | 26 jun 2026 | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and… |
| CVE-2026-48930 | Crítica (9.8) | 0.32% | — | 26 jun 2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines:… |
| CVE-2026-48928 | Media (5.4) | 0.22% | — | 26 jun 2026 | A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. |
| CVE-2026-48619 | Alta (7.5) | 0.64% | — | 26 jun 2026 | A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js… |
| CVE-2026-48618 | Media (6.5) | 3.2% | — | 26 jun 2026 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to… |
| CVE-2026-48615 | Alta (7.5) | 0.40% | — | 26 jun 2026 | A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths… |
| CVE-2026-48931 | Baja (3.7) | 0.34% | — | 22 jun 2026 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**,… |
| CVE-2026-48937 | Alta (7.5) | 0.57% | — | 18 jun 2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**. |
| CVE-2026-48617 | Alta (8.2) | 0.32% | — | 18 jun 2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected… |
| CVE-2026-21717 | Media (5.9) | 0.27% | — | 30 mar 2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's… |
| CVE-2026-21716 | Baja (3.3) | 0.15% | — | 30 mar 2026 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`)… |
| CVE-2026-21715 | Baja (3.3) | 0.16% | — | 30 mar 2026 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result,… |
| CVE-2026-21714 | Media (5.3) | 0.45% | — | 30 mar 2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends… |
| CVE-2026-21713 | Media (5.9) | 0.39% | — | 30 mar 2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat… |
| CVE-2026-21711 | Media (5.3) | 0.18% | — | 30 mar 2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result,… |
| CVE-2026-21710 | Alta (7.5) | 25% | — | 30 mar 2026 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]`… |
| CVE-2026-21712 | Media (6.5) | 0.32% | — | 30 mar 2026 | A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.